THREATOPS
THREAT OPSThreat News › DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

highrapid7Published 2026-09-04

<h2><span style="font-size: undefined;">Overview</span></h2><p style="direction: ltr;"><span style="font-size: undefined;">A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty, atd,

Attributed threat actors

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors