North Korean-linked hackers are compromising South Korean automotive and media firms by embedding a sophisticated "ted backdoor" directly into the source code of HAProxy load balancing software.
Key Points
- Researchers at Rapid7 identified a Linux toolkit that integrates malicious code into HAProxy version 2.8.12 using its native filter API.
- The backdoor intercepts HTTP traffic and executes remote commands by triggering a hidden mode via requests for a specific fake image file.
- Malicious activity is erased from internal logs and statistics, allowing the malware to perform credential harvesting and surveillance without leaving a trace.
- The campaign also deploys trojanized versions of standard Linux daemons, including crond, agetty, and sshd, to maintain persistence and log administrator passwords.
- Evidence, including infrastructure and encryption methods, suggests the involvement of North Korean state-sponsored actors, potentially linked to APT37 or the Lazarus Group.