← Back to news

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

Rapid7 Blog04/09/2026, 12:00
Read full article →

Summary

AI-Generated

Key Points:

  • A new Linux toolkit, attributed to DPRK APTs, targets South Korean media and automotive sectors using the "ted backdoor" and "curlRAT" for long-term espionage.
  • The toolkit allows remote command execution, credential harvesting, and traffic manipulation on compromised HAProxy servers. It exploits vulnerabilities in public-facing applications, particularly Groupware portals.
  • Immediate actions include monitoring for unusual HAProxy behavior, implementing strict access controls on exposed services, and conducting thorough security assessments of web applications.

Technical Details: The campaign utilizes a HAProxy filter API for injection and employs custom encryption methods (XOR and substitution ciphers) for data protection. Initial access is likely gained through exploiting CVEs related to Groupware portals.

MITRE ATT&CK Techniques:

  • T1190 - Exploit Public-Facing Application (Initial Access)
  • T1059.004 - Unix Shell (Execution)
  • T1106 - Native API (Execution)
  • T1574.006 - Hijack Execution Flow: Dynamic Linker (Persistence)
  • T1543 - Create or Modify System Process (Persistence)
  • T1548 - Abuse Elevation Control Mechanism (Privilege Escalation)
  • T1036.005 - Masquerade: Match Legitimate Name (Defense Evasion)
  • T1070.002 - Clear Linux Logs (Defense Evasion)
  • T1070.006 - Timestomp (Defense Evasion)
  • T1562.006 - Disable or Modify OS Logging (Defense Evasion)
  • T1027 - Obfuscated Files or Information (Defense Evasion)
  • T1497.001 - Virtualization/Sandbox Evasion (Defense Evasion)
  • T1556.003 - Modify Authentication Process: Pluggable Authentication Modules (Credential Access)
  • T1539 - Steal Web Session Cookie (Credential Access)
  • T1082 - System Information Discovery (Discovery)
  • T1057 - Process Discovery (Discovery)
  • T1185 - Browser Session Hijacking (Collection)
  • T1119 - Automated Collection (Collection)
  • T1071.001 - Application Layer Protocol: Web Protocols (C2)
  • T1132.001 - Data Encoding: Standard Encoding (C2)

IOCs Mentioned:

  • Domains: img.monderhouse.space, img.darklights.store, img.responsive.pstatic.autos
  • SHA256 Hashes: 5db1b6d52faf60b4f32d6fd0c7c938e4d05d29a14c32ded4a9668357c08b6a91, 94630b96f628c96a6bff7904b40ffc9ad67c86f8a4ff6080c3b524831c93f40272e70936f0dbe459142a1d867617c35f8d0cce

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.