Executive Summary
In September 2026, North Korean state-sponsored actors deployed a sophisticated backdoor called 'Ted' by compromising HAProxy load balancers at two South Korean organizations in the automotive and media sectors. The attackers replaced legitimate HAProxy binaries with trojanized versions containing embedded malware that intercepted web traffic and served altered pages to selected visitors. The implant operated covertly by handling command-and-control requests without reaching backend servers, erasing traces from connection logs and statistics. The attack toolkit included additional trojans targeting system binaries like sshd and crond, along with a companion remote access trojan called curlRAT that maintained persistent access to compromised systems.
This incident highlights the evolving sophistication of supply chain attacks where legitimate infrastructure components are weaponized to establish persistent footholds in critical networks. The attack demonstrates advanced techniques for traffic manipulation and steganographic communication that bypass traditional security controls focused on network perimeter defense.
Why This Matters Now
State-sponsored actors are increasingly targeting critical infrastructure through supply chain compromises and traffic manipulation techniques that evade traditional security controls, requiring organizations to implement zero-trust architectures with comprehensive traffic inspection and behavioral analysis capabilities.
Attack Path Analysis
North Korean APT actors compromised two South Korean organizations through suspected exposed Groupware portals, escalated to root privileges, and deployed a sophisticated Ted backdoor directly compiled into HAProxy load balancers. The implant intercepted web traffic, established covert C2 channels disguised as legitimate HTTP responses, and selectively served altered pages to filtered victims while evading detection through connection counter manipulation.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers likely exploited exposed Groupware portal vulnerabilities to gain initial foothold on victim networks in automotive and media sectors
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Compromise Client Software Binary
Traffic Signaling: Port Knocking
Indicator Removal on Host: Clear Command History
Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay
Masquerading: Match Legitimate Name or Location
Exfiltration Over C2 Channel
Web Service: Bidirectional Communication
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – File Integrity Monitoring
Control ID: 11.5.1
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Network Traffic Visibility and Analytics
Control ID: Network Environment
NIS2 Directive – Cybersecurity Measures
Control ID: Article 21
ISO 27001 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Automotive
Advanced persistent threats targeting HAProxy load balancers compromise web traffic interception capabilities, requiring enhanced encrypted traffic monitoring and zero trust segmentation implementations.
Broadcast Media
State-sponsored attackers manipulating web content delivery through trojanized infrastructure necessitates strengthened egress security policies and multicloud visibility controls for content integrity.
Telecommunications
Infrastructure backdoors enabling traffic interception expose critical communication systems to lateral movement attacks, demanding improved east-west traffic security and anomaly detection capabilities.
Financial Services
APT campaigns compromising load balancer infrastructure threaten transaction integrity and compliance requirements, necessitating enhanced kubernetes security and inline intrusion prevention systems.
Sources
- New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffichttps://thehackernews.com/2026/09/new-ted-backdoor-hides-inside-victims.htmlVerified
- TR-24-014: DPRK APTs' 'Ted' Backdoor and 'curlRAT' Target South Korean Media and Automotive Sectorshttps://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors/Verified
- Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New GOMIR Family Varianthttps://www.enki.co.kr/en/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variantVerified
- Operation SyncHole: Watering Hole Attacks by Lazarushttps://securelist.com/operation-synchole-watering-hole-attacks-by-lazarus/116326/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have constrained this North Korean APT's movement across virtualized infrastructure by enforcing workload segmentation and controlling east-west traffic flows. The attack's blast radius and lateral expansion through compromised load balancers would likely have been significantly reduced.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial compromise through exposed portals would likely still occur, but CNSF micro-segmentation could have limited the attacker's ability to expand beyond the initially compromised workload boundary
Control: Zero Trust Segmentation
Mitigation: While local privilege escalation may still succeed, zero trust segmentation would likely restrict the scope of compromised workloads and limit access to sensitive network segments even with elevated privileges
Control: East-West Traffic Security
Mitigation: Lateral movement across virtualized infrastructure would likely be significantly constrained by east-west traffic inspection and policy enforcement, limiting the attacker's ability to deploy beacons across multiple hosts
Control: Multicloud Visibility & Control
Mitigation: C2 communications through compromised load balancers would likely be detected and constrained through enhanced visibility into traffic flows and anomalous connection patterns across the multicloud environment
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration through compromised web infrastructure would likely be constrained by egress policies that monitor and control outbound traffic flows, limiting the attacker's ability to transfer sensitive information
Residual impact would likely be confined to initially compromised web assets, with reduced ability to expand watering hole operations across segmented network boundaries and limited scope for sustained intelligence collection
Impact at a Glance
Affected Business Functions
- Web Load Balancing Services
- Customer Web Portal Access
- Media Content Delivery
- Automotive Customer Services
Estimated downtime: 7 days
Estimated loss: $150,000
Compromised web traffic interception capabilities affecting customer browsing sessions, potential exposure of authentication credentials through trojanized SSH daemon, and selective content manipulation targeting specific visitors based on IP address and user-agent filtering.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy Zero Trust Segmentation with microsegmentation policies to prevent lateral movement between compromised systems and critical infrastructure components like load balancers
- • Implement Egress Security & Policy Enforcement to detect and block unauthorized outbound communications to attacker C2 domains and prevent data exfiltration through compromised web traffic
- • Enable Multicloud Visibility & Control with centralized monitoring to detect anomalous traffic patterns, connection counter manipulations, and suspicious automation accessing critical network infrastructure
- • Deploy Threat Detection & Anomaly Response capabilities to establish behavioral baselines for system binaries and detect unauthorized modifications to critical services like HAProxy, SSH, and cron daemons
- • Implement East-West Traffic Security controls to monitor and restrict service-to-service communications, ensuring compromised load balancers cannot freely access backend systems or manipulate internal traffic flows



