Cybersecurity
Rapid7 finds ted implant in South Korean HAProxy builds
Rapid7 Labs said it found the ted implant compiled into trojanised HAProxy binaries used by two South Korean organisations, but said its evidence only supported medium-confidence attribution and no intrusion timeline.
- Rapid7 Labs said it found a previously undocumented Linux toolkit inside trojanised HAProxy load balancers used by two South Korean organisations.
- The implant was named ted in debug strings, and Rapid7 said it intercepted traffic for selected visitors while keeping its C2 exchanges out of backend logs and HAProxy counters.
- Rapid7 said its evidence supported only medium-confidence attribution to North Korean state-sponsored actors and did not establish how the attackers got in or when.
- Rapid7 said part of its attribution path came from maltrail and ThreatFox, and it used the cluster labels APT37, Lazarus and Kimsuky.
- The report compared the delivery model with a July campaign documented by AhnLab and ENKI WhiteHat against AnySign4PC.
Rapid7 Labs said it found a Linux toolkit inside altered HAProxy load balancers used by two South Korean organisations. The implant was identified as ted from debug strings, and Rapid7 said it intercepted traffic for selected visitors while serving changed pages.
Rapid7 said command traffic never reached a backend server and did not appear in HAProxy's counters. It said a request had to carry a User-Agent, match URL and referer rules, and pass either client-address filtering or a key in Accept-Language before the implant would switch into command mode.
Rapid7 said its evidence did not show a timeline or the first foothold. Its initial-access idea rested on ENKI research tied to a groupware vendor compromise through a mail-server flaw, and it said the attribution path also used maltrail, ThreatFox and the labels APT37, Lazarus and Kimsuky. Mandiant had said overlapping tooling across North Korean clusters made exact attribution harder.
The stager only ran where HAProxy or cron was already present and checked for root before it wrote files. Rapid7 also found related code in other trojanised system binaries and a companion RAT called curlRAT, which changed its beacon interval when flagged and quit on non-virtual hosts. It distinguished that family from CurlBack RAT, which it tied to SideCopy, and it pointed to a July watering-hole campaign documented by AhnLab and ENKI WhiteHat against AnySign4PC.
Named in this story
Companies
- Mandiant
- said precise attribution would be harder
- AhnLab
- documented a similar watering-hole campaign in July
Organisations
- Rapid7 Labs
- attributed the toolkit and published the report
- APT37
- was the label used for the domain list in maltrail
- Lazarus
- was named in the delivery-model attribution
- Kimsuky
- was named in the initial-access hypothesis
- ENKI
- supplied research on a groupware vendor compromise
- SideCopy
- was the Pakistan-linked group tied to CurlBack RAT
- ENKI WhiteHat
- documented the July campaign with AhnLab
Products and systems
- HAProxy
- was the load balancer whose binary was altered
- ted
- was the name found in debug strings for the implant
- maltrail
- listed the domains Rapid7 used for attribution
- ThreatFox
- supplied sightings of the same domains
- curlRAT
- was a companion RAT with timer-based beaconing
- CurlBack RAT
- was a separate family with a similar name
- AnySign4PC
- was the signing client targeted in that campaign
Places
- South Korea
- was where the two victim organisations were based
How the source tells it
The source read as a technical investigative report with cautious attribution and no strong emotive framing.
No emotive framing was found in the original.