#remotecommandexecution — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #remotecommandexecution, aggregated by home.social.
-
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
A previously undocumented Linux toolkit has been targeting South Korean automotive and media organizations with minimal detection since early 2025. The campaign employs a HAProxy instance called ted backdoor, compiled within the victim's existing HAProxy version 2.8.12, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This sophisticated framework enables remote command execution, malicious script injection into web traffic, credential harvesting, and long-term surveillance. The ted backdoor uses HAProxy's native filter API and internal structures to intercept SSL-decrypted HTTP traffic while maintaining legitimate load balancing operations. Operating alongside are an SSH keylogger, a curl-based RAT with HAProxy health monitoring capabilities, and a deployment stager. The toolkit is attributed with medium confidence to DPRK APTs based on targeting patterns, simple XOR-based encryption schemes, custom substitution ciphers, and C2 infrastructure associated with APT37.
Pulse ID: 6a9af7a5158ae188847551b5
Pulse Link: https://otx.alienvault.com/pulse/6a9af7a5158ae188847551b5
Pulse Author: AlienVault
Created: 2026-09-04 16:53:57Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APT37 #BackDoor #CredentialHarvesting #CyberSecurity #DPRK #Encryption #HTTP #InfoSec #KeyLogger #Korea #Linux #Nim #OTX #OpenThreatExchange #Proxy #RAT #RCE #RemoteCommandExecution #SSH #SSL #SouthKorea #Trojan #bot #AlienVault