Rapid7 reported on 4 September 2026 a Linux espionage toolkit found on servers at two South Korean organisations, one in media and one in the automotive sector. Its centrepiece is a backdoor the researchers call ted, compiled into HAProxy 2.8.12 from source using the load balancer’s own filter interface. Sitting inside the process that terminates TLS, it reads decrypted HTTP traffic, harvests cookies and headers, executes commands sent to a hidden request path, can inject scripts into responses for selected visitors and removes its own requests from HAProxy’s statistics.
The trojanised HAProxy version was released upstream in November 2024, which places the activity from late 2024. Samples reached VirusTotal in mid-2025. The command infrastructure went dark in early September 2026. Alongside ted the toolkit carried a curl-based remote access tool, an SSH keylogger, a stager and trojanised copies of crond, agetty, atd, sshd and polkitd for CentOS 7 and Ubuntu 22.04.
Below The Application, Above The Wire
Most web intrusions land in the application or the database. This one sits in the component that every request passes through after decryption and before the application sees it. Nothing in the application logs shows an attacker, because the application received exactly the traffic it always does; the copy was taken a layer down. The corpus filed the edge-device pattern for perimeter appliances at 26-0810b and the Citrix rooting at 26-0927. A rebuilt open-source load balancer is the same idea achieved by recompiling rather than exploiting.
The Attribution, As Offered
Rapid7 attributes the toolkit to North Korea-aligned actors at medium confidence, leaning toward the group tracked as APT37. The evidence cited is infrastructure previously tagged to that group, targeting of South Korean groupware portals consistent with Kimsuky tradecraft, simple cipher choices and watering-hole delivery resembling earlier APT37 operations. No government has attributed it. The file records a vendor assessment with stated confidence, which is what the record allows, and the initial access, likely through exposed groupware or mail portals, has no CVE attached.
Compiled from Rapid7’s technical report and contemporaneous coverage, listed below. Victim organisations are not named by any source. Attribution is the vendor’s at medium confidence and is stated as such. Whether the victims discovered the intrusions themselves was not established. Graded medium. Corrections: corrections@forensicpost.com.