← BACK TO FEED
TAG

apt371 article

North Korean Hackers Hid a Backdoor Inside South Korea's Own Load Balancers

A previously unknown Linux backdoor called "ted" was discovered embedded within trojanized HAProxy load balancers at two South Korean organisations, intercepting web traffic and serving altered pages to targeted visitors while concealing its activity from logs and connection counters. Rapid7 Labs attributed the toolkit with medium confidence to North Korean state-sponsored actors, drawing on overlapping indicators linked to APT37, Lazarus, and Kimsuky, though the evidence was insufficient to establish a definitive timeline or initial access method. The implant does not exploit a HAProxy vulnerability but requires prior code execution on the host, and upgrading HAProxy alone will not remove it from already-compromised systems.

5 Sept 2026