- What: A Linux toolkit is found in trojanized HAProxy targeting South Korean organizations
- Impact: South Korean automotive and media sectors
Threat Intelligence New Linux toolkit found in trojanized HAProxy targeting South Korean organizations September 4, 2026 Share By SC Staff (Adobe Stock) As reported by The Hacker News, a sophisticated Linux toolkit, dubbed "ted" by its creators, has been discovered embedded within trojanized HAProxy load balancers at two South Korean organizations. This toolkit is designed to intercept web traffic and selectively serve modified content to specific visitors, indicating a targeted and stealthy approach by the attackers, according to Rapid7. The implant, identified by Rapid7 Labs with medium confidence as originating from North Korean state-sponsored actors, targets entities in South Korea's automotive and media sectors. The attackers gained access by executing code on the host and replacing the legitimate HAProxy binary, rather than exploiting a vulnerability. This method allows the toolkit to operate undetected, as command-and-control (C2) requests are erased from HAProxy's connection counters, leaving no trace in backend logs or load balancer statistics. The implant filters requests based on specific criteria, including User-Agent, URL, referrer patterns, and client IP addresses, before serving altered pages. It manipulates HTTP headers to conceal modifications. Evidence suggests the attackers may have gained initial access through an exposed Groupware portal, a common Korean enterprise collaboration software. The toolkit also includes a trojanized SSH daemon for capturing passwords and a companion remote access trojan (RAT) named curlRAT. Rapid7 recommends network correlation, memory behavioral analysis, and binary integrity checks for detection. Source: The Hacker News SC Staff Related Threat Intelligence Breeze Comet threat actor targets Brazilian financial sector with sophisticated attacks SC Staff September 2, 2026 Breeze Comet gains initial access through password spraying and social engineering tactics, impersonating IT support to trick victims into installing Remote Monitoring and Management (RMM) tools like AnyDesk or PowerShell scripts. Threat Intelligence Leaked documents reveal Russian military cyber recruitment pipeline SC Staff September 2, 2026 Originally reported on by DomainTools and GBHackers, the documents detail a force-generation mechanism for General Staff components, including the GRU and the 8th Directorate, which handles protected communications and information security. Threat Management Microsoft identifies ‘TerminalFix’ campaign spreading Python reverse tunnel Laura French September 2, 2026 The campaign uses DLL sideloading and PNG steganography to evade detection. Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Account Harvesting Backdoor Black Hat Botnet Dictionary Attack Distributed Scans Domain Hijacking Dumpster Diving Google Hacking Hybrid Attack You can skip this ad in 5 seconds