Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Rapid7 researchers have uncovered TED, a Linux toolkit that compiles a persistent espionage backdoor directly into victims' HAProxy 2.8.12 binaries. Active since early 2025, the campaigns target South Korean automotive and media firms. The novelty is not the objective — North Korean state-sponsored cyber espionage is well documented — but the depth of integration: the backdoor is built into the victim's own HAProxy 2.8.12 binary, abusing the native filter API to intercept cleartext traffic after SSL termination. Load balancers, traditionally excluded from EDR coverage because they are treated as network appliances, become blind spots with total visibility into application flows.
- The TED backdoor is compiled as an integral part of HAProxy 2.8.12, not as an external process: it generates zero anomalous processes, zero unexpected outbound connections, and zero log entries
- Identified C2 servers — img.darklights.store and img.monderhouse.space — require api_token authentication and implement six command handlers numbered 0 through 5
- Interception occurs post-SSL termination via HAProxy's native filter API, while legitimate load-balancing traffic continues to operate normally
- Rapid7 attributes the activity to North Korean APT groups with medium confidence, based on targeting, obfuscation techniques, and C2 infrastructure overlaps with APT37
How TED Erases the Security Perimeter
The depth of integration is the campaign's defining trait. According to Rapid7, the TED backdoor is not an additional binary running on the system — it is the system. It is compiled directly into the victim's HAProxy 2.8.12 source code, leveraging the load balancer's internal memory pools, event scheduler, and process management infrastructure. Genuine load-balancing traffic continues to function without visible anomalies.
The interception mechanism exploits HAProxy's filter API — a legitimate interface designed to transform, analyze, or block HTTP streams — to capture plaintext traffic after SSL termination has decrypted payloads. In this scenario, the load balancer is no longer a secure passage between the internet and applications; it is the place where data is read in cleartext by an actor extracting it silently.
Concealment is total. The C2 response path writes directly to the raw TCP socket, bypassing HAProxy's logging subsystem. Rapid7 also documented counter-scrubbing techniques that prevent monitoring dashboards from flagging anomalies. As Dark Reading quoted the researchers, "the implant generates no anomalous processes, no unexpected outbound connections and no log entries." No standard behavioral signature can detect it.
"The standout feature of this toolkit is its depth of integration with the target environment. The ted backdoor is compiled as part of the victim's existing HAProxy version 2.8.12." — Rapid7 researchers (via CyberWire)
The C2 Infrastructure: Commands, Timing, and Survival
The command-and-control channel is structured with operational precision. The identified servers — img.darklights.store and img.monderhouse.space — require api_token authentication. Communication implements a jump table with ASCII mode bytes '0' through '5', corresponding to six distinct functions: command execution, configuration writing, staged payload drop, reverse shell, and two additional handlers.
The polling interval is configurable: the default is 43,200 seconds (12 hours), reducible to 30 seconds in fast-poll mode. Each C2 cycle allows 6 connection attempts with 5-second intervals between retries. Command execution output is buffered in a 1 MB space. These metrics, documented in Rapid7's analyzed samples, indicate a design built for long-term persistence rather than rapid mass exfiltration.
Internal obfuscation is consistent: a custom substitution cipher recurs throughout the toolkit to encrypt harvested credentials. The technique is not cryptographically sophisticated — Rapid7 describes it as simple — but it is homogeneous, a pattern observed in other operations attributed to North Korean actors.
The Attack Chain: From Groupware to Persistence
Rapid7's identified victims ran edge web servers with ports 80, 443, and 25 exposed. Port 443 hosted a Groupware portal; port 25 hosted a mail server. This attack surface aligns with the documented modus operandi of Kimsuky, a North Korean APT group known for exploiting RCE vulnerabilities in South Korean groupware mail servers since early 2026. Rapid7 presents this scenario in Figure 1 as an initial access hypothesis, referencing potential Groupware portal CVEs — explicitly unconfirmed as the verified vector in these intrusions.
After initial access, the TED toolkit deploys multiple components: beyond the HAProxy backdoor, it includes an SSH keylogger, CurlRAT (a curl-based RAT), a stager, and trojanized system binaries — crond, agetty, atd, sshd, polkitd. Compilation against HAProxy 2.8.12, released November 22, 2024, provides an earliest possible date for backdoor construction. The oldest samples on VirusTotal date to mid-2025, confirming an activity timeline exceeding one year.
The source does not specify the exact victim count or geographic scope beyond the South Korean context. DPRK attribution remains at medium confidence: researchers do not identify an infrastructural overlap that definitively links TED to a specific group such as Kimsuky or Lazarus, but they underscore consistency with the pattern of targeting strategic South Korean sectors and obfuscation techniques typical of the North Korean ecosystem.
"From the attacker's standpoint, the load balancer is an ideal location because SSL terminates there, it sits in front of all applications, and load balancers are often excluded from endpoint detection coverage because they are treated as network appliances rather than servers" — Rapid7 research team (via Dark Reading)
The Evolution of the DPRK Threat Model
TED represents a qualitative shift in the North Korean threat landscape. Previous campaigns focused on trojanizing legitimate installers — native Windows or Linux software distributed with additional payloads. TED goes further: it does not merely run alongside infrastructure; it fuses with it. As Rapid7 researchers observed via Dark Reading, "TED represents a further step by embedding into production infrastructure rather than running alongside it." Someone, they add, "spent serious time reading HAProxy source code and testing against a live instance."
This approach has architectural consequences for defense. Load balancers handle decrypted traffic, occupy a privileged position in network topology, and are systematically underrepresented in endpoint detection programs. The traditional logic — EDR on user endpoints, VM scanning, application server hardening — leaves a gap where data is most vulnerable: in transit between encryption and application.
Immediate Actions
Organizations running HAProxy or analogous load balancers must reassess their security perimeter with concrete steps:
- Verify compiled binary integrity via known SHA256 hashes and comparison with official HAProxy releases: TED samples cannot be exactly reproduced from official builds due to custom compilation
- Implement memory baselining to detect anomalies in HAProxy's internal memory pool and event scheduler usage — indicators traditional logs do not capture
- Enable out-of-band log correlation from sources independent of the load balancer, to identify discrepancies between observed network traffic and expected log entries
- Reassess EDR/EDR-equivalent coverage on load balancers: if treated as exempt network appliances, they represent a systemic blind spot with visibility into all application flows
The Point of No Return for Network Appliances
The TED campaign demonstrates that the distinction between "network infrastructure" and "endpoint to protect" is operationally dead. Load balancers have access to cleartext data, execution privileges, and often scant attention from security teams. North Korean actors have identified this misalignment and are exploiting it with patience measured in months, not hours.
The most unsettling fact is not the backdoor itself, but its structural invisibility: there is no process to kill, no connection to block, no log to analyze. Future security for these systems will require build-time integrity verification, runtime memory monitoring, and systematic suspicion toward any component that touches decrypted data — regardless of how it is labeled in the IT inventory.
FAQ
Why specifically HAProxy 2.8.12?
The dossier does not clarify whether version 2.8.12 was chosen for particular technical characteristics or simply because it was running on victims at the time of compromise. The release date (November 22, 2024) provides only a post quem terminus for backdoor compilation.
Can TED be detected with standard tools?
According to Rapid7, no: the absence of anomalous processes, unexpected connections, and log entries renders TED invisible to conventional behavioral monitoring. Detection requires binary integrity verification and out-of-band network traffic analysis.
Is DPRK attribution certain?
Rapid7 assigns medium confidence to the attribution. No infrastructural overlaps definitively link TED to a specific group such as Kimsuky or Lazarus at this time.
Information verified against cited sources and current as of publication.
Sources
- https://www.darkreading.com/cyberattacks-data-breaches/cyber-south-korean-media-automotive
- https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors
- https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html
- https://thecyberwire.com/newsletters/daily-briefing/15/171
- https://securityaffairs.com/198495/breaking-news/security-affairs-newsletter-round-593-by-pierluigi-paganini-international-edition.html
- https://www.marketsandmarkets.com/Market-Reports/geography/v2x-cybersecurity-market/south-korea
- https://ics-cert.kaspersky.com/publications/reports/2023/09/25/apt-and-financial-attacks-on-industrial-organizations-in-h1-2023/#korean-speaking-activity
- https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/
- https://www.rapid7.com/cdn/images/blta751583dd18a172b/6a99bbfe49d4290742a52396/ted-backdoor-attack-chain.png
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.