Desk live·
ForensicPost
Nation-state/Espionage/File 26-0904

A Backdoor Compiled Into HAProxy Read South Korean Firms’ Decrypted Traffic for Two Years

Rapid7 found a load balancer rebuilt from source with a filter that intercepts decrypted HTTP, steals cookies and headers, runs commands on a hidden path and scrubs itself from the statistics page. Two organisations in media and automotive are confirmed. Attribution to North Korea is the vendor’s, at medium confidence.

Constructed geometry · not a chart of case data
JurisdictionSouth KoreaSeoulthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetSouth Korean media and automotive firms
ActorDPRK-aligned (Rapid7, medium confidence)
D. Kennedy9 min readConfidence: medium3 sources reviewed

Rapid7 reported on 4 September 2026 a Linux espionage toolkit found on servers at two South Korean organisations, one in media and one in the automotive sector. Its centrepiece is a backdoor the researchers call ted, compiled into HAProxy 2.8.12 from source using the load balancer’s own filter interface. Sitting inside the process that terminates TLS, it reads decrypted HTTP traffic, harvests cookies and headers, executes commands sent to a hidden request path, can inject scripts into responses for selected visitors and removes its own requests from HAProxy’s statistics.

The trojanised HAProxy version was released upstream in November 2024, which places the activity from late 2024. Samples reached VirusTotal in mid-2025. The command infrastructure went dark in early September 2026. Alongside ted the toolkit carried a curl-based remote access tool, an SSH keylogger, a stager and trojanised copies of crond, agetty, atd, sshd and polkitd for CentOS 7 and Ubuntu 22.04.

Below The Application, Above The Wire

Most web intrusions land in the application or the database. This one sits in the component that every request passes through after decryption and before the application sees it. Nothing in the application logs shows an attacker, because the application received exactly the traffic it always does; the copy was taken a layer down. The corpus filed the edge-device pattern for perimeter appliances at 26-0810b and the Citrix rooting at 26-0927. A rebuilt open-source load balancer is the same idea achieved by recompiling rather than exploiting.

The Attribution, As Offered

Rapid7 attributes the toolkit to North Korea-aligned actors at medium confidence, leaning toward the group tracked as APT37. The evidence cited is infrastructure previously tagged to that group, targeting of South Korean groupware portals consistent with Kimsuky tradecraft, simple cipher choices and watering-hole delivery resembling earlier APT37 operations. No government has attributed it. The file records a vendor assessment with stated confidence, which is what the record allows, and the initial access, likely through exposed groupware or mail portals, has no CVE attached.

How we reported this

Compiled from Rapid7’s technical report and contemporaneous coverage, listed below. Victim organisations are not named by any source. Attribution is the vendor’s at medium confidence and is stated as such. Whether the victims discovered the intrusions themselves was not established. Graded medium. Corrections: corrections@forensicpost.com.

Sources
  1. DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectorsRapid7
  2. North Korean Hackers Deploy New Linux Espionage ToolkitSecurityWeek
  3. North Korea-linked Hackers Hide a Backdoor Inside HAProxySecurity Affairs
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary