{"id":1765,"date":"2026-09-18T11:41:37","date_gmt":"2026-09-18T06:11:37","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1765"},"modified":"2026-09-21T14:39:05","modified_gmt":"2026-09-21T09:09:05","slug":"ted-linux-toolkit-north-korean-apt-compromises-haproxy","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\/","title":{"rendered":"TED Linux Toolkit: North Korean APT Compromises HAProxy"},"content":{"rendered":"<p>Rapid7 Labs identified a previously undocumented Linux espionage framework built around an implant it calls the TED backdoor. Security researchers now refer to the broader framework as the TED Linux toolkit. Attackers compiled it directly into HAProxy load balancer software at South Korean media and automotive organizations.<\/p>\n<p>Rapid7 attributes the campaign to a North Korean APT with medium confidence. The assessment cites overlapping<a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-command-and-control-c2\/\"> command-and-control<\/a> infrastructure with APT37, also known as ScarCruft or Ricochet Chollima.<\/p>\n<p>This matters operationally because load balancers terminate SSL traffic before it reaches applications. A malicious module living inside that appliance can read decrypted traffic directly. It never needs a separate interception attack. Many organizations also exclude load balancers from endpoint detection coverage, treating them as network appliances rather than servers.<\/p>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tBook a free demo and explore Hexnode today!<\/a>\r\n    \t\t<\/center><\/p>\n<h2>Living inside the load balancer<\/h2>\n<p>This attack does not exploit a vulnerability in HAProxy itself. Rapid7 found no flaw in HAProxy&#8217;s code that attackers took advantage of. Instead, attackers first needed existing code execution on the host to recompile a legitimate HAProxy 2.8.12 build with a custom plugin, then swap it in for the real binary. This is a post-exploitation technique, not an initial-access exploit.<\/p>\n<p>Once installed, the plugin hooks HAProxy&#8217;s own HTTP parser rather than running as a separate process.<\/p>\n<p>The implant operates in two distinct modes, triggered by two separate mechanisms:<\/p>\n<ul>\n<li><strong>Command mode:<\/strong> A request matching a hidden trigger path switches the implant into command mode. This lets an operator run commands or update its configuration remotely.<\/li>\n<li><strong>Passive filter mode:<\/strong> Outside command mode, the implant watches for requests matching operator-defined rules built from Client IP address ranges, User-Agent, URL, and referer headers.<\/li>\n<\/ul>\n<p>Matched requests in passive filter mode trigger one of two actions:<\/p>\n<ul>\n<li>Logging session data quietly for later collection.<\/li>\n<li>Replacing the outgoing response with attacker-supplied content.<\/li>\n<\/ul>\n<p>Rapid7 treats the trigger path and the matching-rule engine as separate mechanisms, not one combined step, and this blog does too:<\/p>\n<ul>\n<li>The trigger path drives command-and-control access.<\/li>\n<li>The matching rules decide which victims see injected content.<\/li>\n<\/ul>\n<p>To hide the activity, the implant decrements HAProxy&#8217;s own internal traffic counters after handling a command. This keeps monitoring dashboards from showing anomalous connection spikes.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/threat-classification.jpeg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>What is Threat Classification?<\/h4><p>Threat classification organizes endpoint alerts by type, severity, and impact.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/what-is-threat-classification\/\" aria-label=\"What is Threat Classification?\"><\/a><\/div><\/div><\/div>\n<h2>Toolkit components and capabilities<\/h2>\n<p>The campaign relies on several components working together rather than one monolithic implant:<\/p>\n<ul>\n<li>The ted backdoor intercepts decrypted HTTP traffic inside HAProxy itself.<\/li>\n<li>curlRAT runs disguised as <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-trojan\/\">trojanized<\/a> system daemons, including crond, agetty, atd, polkitd, and sshd, and handles remote command execution, reverse shells, and beaconing.<\/li>\n<li>A stager profiles the host&#8217;s OS and architecture, then drops the correct trojanized binary for that system.<\/li>\n<li>An <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-secure-shell-ssh\/\">SSH<\/a> keylogger embedded directly within the trojanized sshd binary intercepts plaintext credentials during login.<\/li>\n<\/ul>\n<table style=\"width: 100%;\">\n<thead>\n<tr>\n<th style=\"width: 18.6047%; text-align: left;\"><strong>Component<\/strong><\/th>\n<th style=\"width: 39.7463%; text-align: left;\"><strong>Function<\/strong><\/th>\n<th style=\"width: 40.5919%; text-align: left;\"><strong>Operational Risk<\/strong><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width: 18.6047%;\">ted backdoor<\/td>\n<td style=\"width: 39.7463%;\">Intercepts decrypted HAProxy traffic and injects scripts into responses<\/td>\n<td style=\"width: 40.5919%;\">Exposes session cookies and credentials without breaking TLS<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 18.6047%;\">curlRAT<\/td>\n<td style=\"width: 39.7463%;\">Executes commands and opens shells from trojanized crond, agetty, atd, polkitd, and sshd daemons<\/td>\n<td style=\"width: 40.5919%;\">Gives attackers persistent remote control across internal hosts<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 18.6047%;\">Stager<\/td>\n<td style=\"width: 39.7463%;\">Selects and installs the correct trojanized binary per OS<\/td>\n<td style=\"width: 40.5919%;\">Enables tailored, distro-specific persistence<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 18.6047%;\">SSH keylogger<\/td>\n<td style=\"width: 39.7463%;\">Captures plaintext passwords during SSH logins<\/td>\n<td style=\"width: 40.5919%;\">Supplies credentials for lateral movement<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Attribution: Multiple threads, not one actor<\/h2>\n<p>Rapid7&#8217;s assessment rests on three separate data points. Each supports a different piece of the picture, and the report keeps them distinct rather than merging them into one actor claim.<\/p>\n<h3>Thread one: APT37 infrastructure overlap.<\/h3>\n<p>The campaign&#8217;s hardcoded C2 domains match lists that ThreatFox and Maltrail associate with APT37. Combined with simple XOR and substitution ciphers and a watering-hole delivery model, this supports medium-confidence attribution to a North Korean APT.<\/p>\n<h3>Thread two: Kimsuky-style initial access.<\/h3>\n<p>Exposed Groupware login portals and mail servers at the victims match tradecraft that ENKI WhiteHat previously documented from Kimsuky. This points to a plausible<a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-initial-access-in-cybersecurity\/\"> initial access<\/a> method, not confirmed attribution.<\/p>\n<h3>Thread three: Lazarus timeline overlap.<\/h3>\n<p>The campaign&#8217;s watering-hole approach and delivery window resemble Operation SyncHole, a Lazarus campaign that Kaspersky tracked from November 2024 through February 2025.<\/p>\n<p>A few points keep these threads properly separated:<\/p>\n<ul>\n<li>Rapid7 treats APT37 and Lazarus as distinct DPRK-linked clusters operating under different agencies, per Mandiant&#8217;s assessment.<\/li>\n<li>No single piece of evidence confirms a single actor.<\/li>\n<li>The report presents this as three parallel observations, not one unified attribution.<\/li>\n<\/ul>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-.jpg?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity kit\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-.jpg?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--300x225.jpg?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--768x576.jpg?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--133x100.jpg?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity kit\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Cybersecurity kit\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Download this cybersecurity kit for blueprints, frameworks, checklists, and policy templates for enterprise IT teams.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/resource-kits\/cybersecurity-kit\/'>\n                            DOWNLOAD\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>Detection challenges<\/h2>\n<p>Rapid7&#8217;s researchers say the implant produces no anomalous processes, no unexpected outbound connections, and no log entries under normal operation. Its response traffic writes directly to the raw TCP socket and bypasses HAProxy&#8217;s own logging subsystem entirely.<\/p>\n<p>This means dashboards built on the appliance&#8217;s self-reported logs will not show the compromise. Detection requires checks that do not depend on the load balancer&#8217;s own telemetry.<\/p>\n<h3>Operational Recommendations<\/h3>\n<p>Security teams managing HAProxy or similar reverse proxies should prioritize:<\/p>\n<ul>\n<li>Verifying binary integrity against known-good HAProxy builds rather than trusting version strings alone.<\/li>\n<li>Auditing process memory for injected filters or unexpected loaded modules.<\/li>\n<li>Comparing on-device logs against independent, out-of-band network capture.<\/li>\n<li>Applying the same detection discipline used on application servers to any appliance that terminates SSL or loads runtime modules.<\/li>\n<\/ul>\n<p>Endpoint patch hygiene on admin workstations does not remediate this issue. The compromise lives inside the load balancer&#8217;s own compiled code, not on the devices administrators use to manage it.<\/p>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What is the TED Linux toolkit?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>It is the name security teams use for a Linux espionage framework Rapid7 uncovered. Rapid7 calls the core implant the ted backdoor, and it works alongside curlRAT, a stager, and an SSH keylogger.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">How did attackers gain initial access?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Rapid7 has not publicly confirmed the entry point. Two victims ran exposed Groupware and mail server portals consistent with known Kimsuky targeting patterns, but this remains unconfirmed.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Does updating HAProxy remove the threat?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Not by itself. The implant is compiled directly into the HAProxy binary, so a version upgrade alone will not catch a rebuilt malicious binary. Organizations need binary integrity checks and independent log correlation alongside any update.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n<h3>Conclusion<\/h3>\n<p>This campaign shows that trusted infrastructure, not just endpoints, needs active scrutiny. A load balancer that terminates SSL and loads runtime modules carries the same exposure as any application server handling sensitive data.<\/p>\n<p>Security teams should treat network appliances with the same investigative rigor they apply elsewhere. Independent network correlation, memory analysis, and binary verification catch what appliance-native logging alone will miss.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Stay ahead of infrastructure-level threats. <\/h5><p>Get weekly threat intelligence built for security operations teams. <\/p><a href=\"https:\/\/www.hexnode.com\/xdr\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> SIGN UP NOW<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Rapid7 Labs identified a previously undocumented Linux espionage framework built around an implant it calls&#8230;<\/p>\n","protected":false},"author":5,"featured_media":1766,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13,15],"class_list":["post-1765","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity-abuse","category-malware","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>TED Linux Toolkit Targets HAProxy in North Korean APT Campaign<\/title>\n<meta name=\"description\" content=\"A North Korean APT installed a Linux toolkit called TED inside HAProxy load balancers to harvest credentials and hide activity.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"TED Linux Toolkit Targets HAProxy in North Korean APT Campaign\" \/>\n<meta property=\"og:description\" content=\"A North Korean APT installed a Linux toolkit called TED inside HAProxy load balancers to harvest credentials and hide activity.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-18T06:11:37+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-21T09:09:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/ted-linux-toolkit.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sophia Hart\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sophia Hart\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\\\/\"},\"author\":{\"name\":\"Sophia Hart\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\"},\"headline\":\"TED Linux Toolkit: North Korean APT Compromises HAProxy\",\"datePublished\":\"2026-09-18T06:11:37+00:00\",\"dateModified\":\"2026-09-21T09:09:05+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\\\/\"},\"wordCount\":1120,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ted-linux-toolkit.jpeg?format=webp\",\"articleSection\":[\"Identity Abuse\",\"Malware\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\\\/\",\"name\":\"TED Linux Toolkit Targets HAProxy in North Korean APT Campaign\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ted-linux-toolkit.jpeg?format=webp\",\"datePublished\":\"2026-09-18T06:11:37+00:00\",\"dateModified\":\"2026-09-21T09:09:05+00:00\",\"description\":\"A North Korean APT installed a Linux toolkit called TED inside HAProxy load balancers to harvest credentials and hide activity.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ted-linux-toolkit.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ted-linux-toolkit.jpeg?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"ted linux toolkit\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"TED Linux Toolkit: North Korean APT Compromises HAProxy\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\",\"name\":\"Sophia Hart\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"caption\":\"Sophia Hart\"},\"description\":\"A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions\u2014without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable\u2014politely.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/sophia-hart\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"TED Linux Toolkit Targets HAProxy in North Korean APT Campaign","description":"A North Korean APT installed a Linux toolkit called TED inside HAProxy load balancers to harvest credentials and hide activity.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\/","og_locale":"en_US","og_type":"article","og_title":"TED Linux Toolkit Targets HAProxy in North Korean APT Campaign","og_description":"A North Korean APT installed a Linux toolkit called TED inside HAProxy load balancers to harvest credentials and hide activity.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-18T06:11:37+00:00","article_modified_time":"2026-09-21T09:09:05+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/ted-linux-toolkit.jpeg?format=webp","type":"image\/jpeg"}],"author":"Sophia Hart","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Sophia Hart","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\/"},"author":{"name":"Sophia Hart","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430"},"headline":"TED Linux Toolkit: North Korean APT Compromises HAProxy","datePublished":"2026-09-18T06:11:37+00:00","dateModified":"2026-09-21T09:09:05+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\/"},"wordCount":1120,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/ted-linux-toolkit.jpeg?format=webp","articleSection":["Identity Abuse","Malware"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\/","url":"https:\/\/www.hexnode.com\/threat-watch\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\/","name":"TED Linux Toolkit Targets HAProxy in North Korean APT Campaign","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/ted-linux-toolkit.jpeg?format=webp","datePublished":"2026-09-18T06:11:37+00:00","dateModified":"2026-09-21T09:09:05+00:00","description":"A North Korean APT installed a Linux toolkit called TED inside HAProxy load balancers to harvest credentials and hide activity.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/ted-linux-toolkit.jpeg?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/ted-linux-toolkit.jpeg?format=webp","width":1340,"height":700,"caption":"ted linux toolkit"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/ted-linux-toolkit-north-korean-apt-compromises-haproxy\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"TED Linux Toolkit: North Korean APT Compromises HAProxy"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430","name":"Sophia Hart","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","caption":"Sophia Hart"},"description":"A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions\u2014without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable\u2014politely.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/sophia-hart\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1765","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1765"}],"version-history":[{"count":6,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1765\/revisions"}],"predecessor-version":[{"id":1812,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1765\/revisions\/1812"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1766"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1765"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1765"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}