DPRK hackers compromise South Korean media via trojanized HAProxy load balancers
DPRK-linked threat actors have compromised South Korean media and automotive firms by deploying the Ted backdoor and CurlRAT malware within modified HAProxy load balancers. The intrusion allows attackers to maintain persistent access, capture session cookies, and inject malicious scripts into web traffic at the network edge.
Key Takeaways
- Attackers deployed the Ted backdoor by compiling malicious code directly into HAProxy version 2.8.12 to inspect decrypted web traffic.
- Rapid7 identified the toolkit which includes CurlRAT for remote command execution and a watchdog to monitor service status.
- The malware captures session cookies, injects malicious scripts into web pages, and uses an SSH keylogger to steal credentials.
- Intrusions likely began in early 2025, targeting exposed groupware portals and mail services on ports 80, 443, and 25.
Why It Matters
The compromise of edge-level load balancers represents a significant threat to media organizations because it allows attackers to manipulate web traffic before it reaches the end user. By embedding the Ted backdoor within legitimate HAProxy builds, threat actors can maintain long-term espionage footholds that bypass standard detection by hiding within trusted system processes. This tactic highlights a shift toward targeting the streaming and media supply chain's infrastructure to harvest credentials and redirect traffic. As regional tensions persist, streaming professionals should monitor for unusual outbound connections from load balancers and verify the integrity of Linux service binaries against known-good versions.
Additional Context
North Korean state-sponsored hacking groups have increasingly focused on media and entertainment infrastructure across South Korea and the broader Asia-Pacific region. In June 2026, a cluster of announcements signaled a shift from isolated AI pilots to production-grade network automation across live telco networks, but the same infrastructure modernization that drives efficiency also expands the attack surface for nation-state actors targeting edge components like load balancers. South Korean media companies, which operate large-scale content delivery networks and streaming platforms, represent high-value targets for intelligence collection and potential disruption campaigns.
The competitive dynamics among network infrastructure vendors are relevant to understanding why HAProxy and similar open-source load balancers are widely deployed in media streaming stacks. Nokia has combined with AWS and Databricks to build a telco AI control layer, positioning its Autonomous Network Fabric as an operating system for radio, core, transport, and service domains. This consolidation of network control planes means that a single compromised component at the edge can affect multiple downstream services, including content delivery and subscriber management systems that media companies rely on. Ericsson has adopted agentic AI to unify telecom operations with a cloud-first blueprint, defining an agentic service experience layer spanning customer journeys, revenue management, and network operations. The convergence of these platforms creates both operational efficiency and concentrated risk if edge infrastructure is compromised.
From a technical standpoint, the use of trojanized HAProxy builds represents a sophisticated supply-chain attack vector that bypasses traditional perimeter defenses. Ericsson and Nokia are diverging on AI-RAN strategy, with Nokia building its entire RAN strategy on a close partnership with Nvidia and Ericsson pursuing its own commercial AI software subscriptions. As operators and media companies increasingly deploy software-defined networking components at the edge, the integrity of open-source binaries like HAProxy becomes critical. The Ted backdoor and CurlRAT toolset described in this campaign demonstrates that DPRK-linked actors are specifically engineering malware to persist within legitimate network infrastructure processes, making detection dependent on binary integrity verification rather than signature-based approaches. highlights how both vendors are positioning AI-driven automation as a path to operational differentiation, but the same automation layers that promise efficiency gains also introduce new vectors for adversaries who can manipulate configuration management systems.
Read full article at cybersecuritynews.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source