Sophia
Hart

TED Linux Toolkit: North Korean APT Compromises HAProxy

Sophia Hart

Sep 18, 2026

6 min read

ted linux toolkit

TL; DR

  • Rapid7 Labs found the TED Linux toolkit compiled directly into HAProxy 2.8.12, giving attackers a filter that reads decrypted HTTP traffic and injects malicious scripts.
  • Rapid7 attributes the campaign to a North Korean APT with medium confidence, citing APT37 C2 overlap, Kimsuky-style initial access tradecraft, and timeline parallels with a separate Lazarus campaign.
  • The toolkit harvested SSH credentials, redirected selected users, ran drive-by-download attacks, and scrubbed HAProxy’s own connection counters to hide its activity.
  • Activity may date back to early 2025, but Rapid7 has not publicly confirmed the exact initial access vector or the full victim count.

Rapid7 Labs identified a previously undocumented Linux espionage framework built around an implant it calls the TED backdoor. Security researchers now refer to the broader framework as the TED Linux toolkit. Attackers compiled it directly into HAProxy load balancer software at South Korean media and automotive organizations.

Rapid7 attributes the campaign to a North Korean APT with medium confidence. The assessment cites overlapping command-and-control infrastructure with APT37, also known as ScarCruft or Ricochet Chollima.

This matters operationally because load balancers terminate SSL traffic before it reaches applications. A malicious module living inside that appliance can read decrypted traffic directly. It never needs a separate interception attack. Many organizations also exclude load balancers from endpoint detection coverage, treating them as network appliances rather than servers.

Book a free demo and explore Hexnode today!

Living inside the load balancer

This attack does not exploit a vulnerability in HAProxy itself. Rapid7 found no flaw in HAProxy’s code that attackers took advantage of. Instead, attackers first needed existing code execution on the host to recompile a legitimate HAProxy 2.8.12 build with a custom plugin, then swap it in for the real binary. This is a post-exploitation technique, not an initial-access exploit.

Once installed, the plugin hooks HAProxy’s own HTTP parser rather than running as a separate process.

The implant operates in two distinct modes, triggered by two separate mechanisms:

  • Command mode: A request matching a hidden trigger path switches the implant into command mode. This lets an operator run commands or update its configuration remotely.
  • Passive filter mode: Outside command mode, the implant watches for requests matching operator-defined rules built from Client IP address ranges, User-Agent, URL, and referer headers.

Matched requests in passive filter mode trigger one of two actions:

  • Logging session data quietly for later collection.
  • Replacing the outgoing response with attacker-supplied content.

Rapid7 treats the trigger path and the matching-rule engine as separate mechanisms, not one combined step, and this blog does too:

  • The trigger path drives command-and-control access.
  • The matching rules decide which victims see injected content.

To hide the activity, the implant decrements HAProxy’s own internal traffic counters after handling a command. This keeps monitoring dashboards from showing anomalous connection spikes.

Toolkit components and capabilities

The campaign relies on several components working together rather than one monolithic implant:

  • The ted backdoor intercepts decrypted HTTP traffic inside HAProxy itself.
  • curlRAT runs disguised as trojanized system daemons, including crond, agetty, atd, polkitd, and sshd, and handles remote command execution, reverse shells, and beaconing.
  • A stager profiles the host’s OS and architecture, then drops the correct trojanized binary for that system.
  • An SSH keylogger embedded directly within the trojanized sshd binary intercepts plaintext credentials during login.
Component Function Operational Risk
ted backdoor Intercepts decrypted HAProxy traffic and injects scripts into responses Exposes session cookies and credentials without breaking TLS
curlRAT Executes commands and opens shells from trojanized crond, agetty, atd, polkitd, and sshd daemons Gives attackers persistent remote control across internal hosts
Stager Selects and installs the correct trojanized binary per OS Enables tailored, distro-specific persistence
SSH keylogger Captures plaintext passwords during SSH logins Supplies credentials for lateral movement

Attribution: Multiple threads, not one actor

Rapid7’s assessment rests on three separate data points. Each supports a different piece of the picture, and the report keeps them distinct rather than merging them into one actor claim.

Thread one: APT37 infrastructure overlap.

The campaign’s hardcoded C2 domains match lists that ThreatFox and Maltrail associate with APT37. Combined with simple XOR and substitution ciphers and a watering-hole delivery model, this supports medium-confidence attribution to a North Korean APT.

Thread two: Kimsuky-style initial access.

Exposed Groupware login portals and mail servers at the victims match tradecraft that ENKI WhiteHat previously documented from Kimsuky. This points to a plausible initial access method, not confirmed attribution.

Thread three: Lazarus timeline overlap.

The campaign’s watering-hole approach and delivery window resemble Operation SyncHole, a Lazarus campaign that Kaspersky tracked from November 2024 through February 2025.

A few points keep these threads properly separated:

  • Rapid7 treats APT37 and Lazarus as distinct DPRK-linked clusters operating under different agencies, per Mandiant’s assessment.
  • No single piece of evidence confirms a single actor.
  • The report presents this as three parallel observations, not one unified attribution.
cybersecurity kit

Cybersecurity kit

Download this cybersecurity kit for blueprints, frameworks, checklists, and policy templates for enterprise IT teams.

DOWNLOAD

Detection challenges

Rapid7’s researchers say the implant produces no anomalous processes, no unexpected outbound connections, and no log entries under normal operation. Its response traffic writes directly to the raw TCP socket and bypasses HAProxy’s own logging subsystem entirely.

This means dashboards built on the appliance’s self-reported logs will not show the compromise. Detection requires checks that do not depend on the load balancer’s own telemetry.

Operational Recommendations

Security teams managing HAProxy or similar reverse proxies should prioritize:

  • Verifying binary integrity against known-good HAProxy builds rather than trusting version strings alone.
  • Auditing process memory for injected filters or unexpected loaded modules.
  • Comparing on-device logs against independent, out-of-band network capture.
  • Applying the same detection discipline used on application servers to any appliance that terminates SSL or loads runtime modules.

Endpoint patch hygiene on admin workstations does not remediate this issue. The compromise lives inside the load balancer’s own compiled code, not on the devices administrators use to manage it.

FAQs

It is the name security teams use for a Linux espionage framework Rapid7 uncovered. Rapid7 calls the core implant the ted backdoor, and it works alongside curlRAT, a stager, and an SSH keylogger.

Rapid7 has not publicly confirmed the entry point. Two victims ran exposed Groupware and mail server portals consistent with known Kimsuky targeting patterns, but this remains unconfirmed.

Not by itself. The implant is compiled directly into the HAProxy binary, so a version upgrade alone will not catch a rebuilt malicious binary. Organizations need binary integrity checks and independent log correlation alongside any update.

Conclusion

This campaign shows that trusted infrastructure, not just endpoints, needs active scrutiny. A load balancer that terminates SSL and loads runtime modules carries the same exposure as any application server handling sensitive data.

Security teams should treat network appliances with the same investigative rigor they apply elsewhere. Independent network correlation, memory analysis, and binary verification catch what appliance-native logging alone will miss.

Share

Sophia Hart

A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions—without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable—politely.