North Korea-linked hackers used a backdoored HAProxy toolkit to spy on South Korean automotive and media organizations

North Korea-linked hackers used a new Linux espionage toolkit to secretly monitor South Korean automotive and media organizations for long periods. Rapid7 says the toolkit embeds a custom backdoor called 'ted' into HAProxy 2.8.12 and includes trojanized agetty, atd, crond, polkitd, and sshd, plus CurlRAT, an SSH keylogger, and a stager. Initial access came through exploitation of a Groupware login portal vulnerability, after which the attackers harvested credentials, moved laterally, and used the HAProxy implant to inject web traffic, steal sessions, and run commands.
Why it matters: This matters because the attackers modified core Linux and traffic-handling components to hide long-term spying inside normal network activity. Organizations running Linux edge servers, HAProxy, or exposed groupware portals should urgently investigate for compromise, review SSH credentials and sessions, and look for tampered system binaries and unusual HAProxy builds.

Sources

North Korean Hackers Deploy New Linux Espionage Toolkit
Ionut Arghire 2026.09.07 100% relevant
This article establishes a distinct campaign centered on a newly reported Linux espionage toolkit with a HAProxy-embedded backdoor targeting South Korean automotive and media entities; it does not match an existing tracked event in the list.
← Back to all stories