ARTIFICE DAILY AI + CYBER SECURITY BRIEFING

Cybersecurity

Rapid7 finds ted implant in South Korean HAProxy builds

Rapid7 Labs said it found the ted implant compiled into trojanised HAProxy binaries used by two South Korean organisations, but said its evidence only supported medium-confidence attribution and no intrusion timeline.

The Hacker News

Rapid7 Labs said it found a Linux toolkit inside altered HAProxy load balancers used by two South Korean organisations. The implant was identified as ted from debug strings, and Rapid7 said it intercepted traffic for selected visitors while serving changed pages.

Rapid7 said command traffic never reached a backend server and did not appear in HAProxy's counters. It said a request had to carry a User-Agent, match URL and referer rules, and pass either client-address filtering or a key in Accept-Language before the implant would switch into command mode.

Rapid7 said its evidence did not show a timeline or the first foothold. Its initial-access idea rested on ENKI research tied to a groupware vendor compromise through a mail-server flaw, and it said the attribution path also used maltrail, ThreatFox and the labels APT37, Lazarus and Kimsuky. Mandiant had said overlapping tooling across North Korean clusters made exact attribution harder.

The stager only ran where HAProxy or cron was already present and checked for root before it wrote files. Rapid7 also found related code in other trojanised system binaries and a companion RAT called curlRAT, which changed its beacon interval when flagged and quit on non-virtual hosts. It distinguished that family from CurlBack RAT, which it tied to SideCopy, and it pointed to a July watering-hole campaign documented by AhnLab and ENKI WhiteHat against AnySign4PC.

Named in this story

Companies

Mandiant
said precise attribution would be harder
AhnLab
documented a similar watering-hole campaign in July

Organisations

Rapid7 Labs
attributed the toolkit and published the report
APT37
was the label used for the domain list in maltrail
Lazarus
was named in the delivery-model attribution
Kimsuky
was named in the initial-access hypothesis
ENKI
supplied research on a groupware vendor compromise
SideCopy
was the Pakistan-linked group tied to CurlBack RAT
ENKI WhiteHat
documented the July campaign with AhnLab

Products and systems

HAProxy
was the load balancer whose binary was altered
ted
was the name found in debug strings for the implant
maltrail
listed the domains Rapid7 used for attribution
ThreatFox
supplied sightings of the same domains
curlRAT
was a companion RAT with timer-based beaconing
CurlBack RAT
was a separate family with a similar name
AnySign4PC
was the signing client targeted in that campaign

Places

South Korea
was where the two victim organisations were based

How the source tells it

The source read as a technical investigative report with cautious attribution and no strong emotive framing.

No emotive framing was found in the original.