home.social

#remotecommandexecution — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #remotecommandexecution, aggregated by home.social.

  1. DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

    A previously undocumented Linux toolkit has been targeting South Korean automotive and media organizations with minimal detection since early 2025. The campaign employs a HAProxy instance called ted backdoor, compiled within the victim's existing HAProxy version 2.8.12, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This sophisticated framework enables remote command execution, malicious script injection into web traffic, credential harvesting, and long-term surveillance. The ted backdoor uses HAProxy's native filter API and internal structures to intercept SSL-decrypted HTTP traffic while maintaining legitimate load balancing operations. Operating alongside are an SSH keylogger, a curl-based RAT with HAProxy health monitoring capabilities, and a deployment stager. The toolkit is attributed with medium confidence to DPRK APTs based on targeting patterns, simple XOR-based encryption schemes, custom substitution ciphers, and C2 infrastructure associated with APT37.

    Pulse ID: 6a9af7a5158ae188847551b5
    Pulse Link: otx.alienvault.com/pulse/6a9af
    Pulse Author: AlienVault
    Created: 2026-09-04 16:53:57

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APT37 #BackDoor #CredentialHarvesting #CyberSecurity #DPRK #Encryption #HTTP #InfoSec #KeyLogger #Korea #Linux #Nim #OTX #OpenThreatExchange #Proxy #RAT #RCE #RemoteCommandExecution #SSH #SSL #SouthKorea #Trojan #bot #AlienVault