North Korea-linked Ted backdoor hits South Korean firms
Researchers found a hidden espionage toolkit compiled directly into the HAProxy load balancers of two South Korean organizations, in the automotive and media sectors. The implant, nicknamed Ted, intercepted web traffic and let attackers run commands and swap in altered web pages while erasing its own traces from server logs. Rapid7 says it ran undetected for roughly nine to ten months and links it with medium confidence to North Korean state-backed hackers.
- Started
- Sep 4, 2026
- Latest activity
- Sep 4, 2026
- Attributed to
- North Korea (state-linked)Suspected
- Where
- South Korea
- Sectors
- Media
- Scale
- two organizations in South Korea's automotive and media sectors
Current status
No credible update was found after September 7, 2026; the last known report remains SecurityWeek's September 7 account.
Contained: The attack has been stopped or blocked. Recovery and investigation are still running.
Who is behind it
Rapid7 Labs attributed the toolkit to North Korean state-sponsored actors with only medium confidence, saying more evidence is needed.
Impact
Attackers gained long-term, largely undetected access to compromised servers, intercepted and altered web traffic shown to selected visitors, and could run commands, upload or download files, and update the implant, all while hiding the activity from normal server logs.
What to do
This does not affect typical readers directly; organizations running HAProxy on Linux should check for unauthorized modifications to their HAProxy binaries and unusual named pipes under /tmp.
Timeline
-
Sep 7, 2026
SecurityWeek reported the campaign also involved trojanized versions of crond, agetty, atd, sshd and polkitd for long-term surveillance.
Containedsecurityweek.com -
Sep 4, 2026
Rapid7 published research describing the Ted backdoor hidden in trojanized HAProxy builds at two South Korean organizations.
Containedthehackernews.com
Sources
- North Korean Hackers Deploy New Linux Espionage Toolkit SecurityWeek Sep 7, 2026
- New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic The Hacker News Sep 4, 2026
- Stamparm/maltrail bug can expose secrets Rapid7 Aug 21, 2026
Related reports
- Espionage Toolkit Concealed in HAProxy Sep 7, 2026
- Stamparm/maltrail bug can expose secrets Aug 21, 2026