DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

Rapid7 Version 2 imported change current

Imported from official source

A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. …

This version

Version
2 of 2
Recorded
September 24, 2026 17:00
Change
Imported change
Content hash
46ad6e8a596ae67880abb276143de7e8
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.