■■■■□ DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors.
TED and CurlRAT are Linux-focused tools attributed with medium confidence to #APT37.
TED is a trojanized HAProxy 2.8.12 build that loads a custom ted_plugin filter.
it hooks the HTTP parser to inspect requests, steal cookies/headers, rewrite responses, and inject decrypted scripts into live traffic while using FIFOs and HTTP opcodes for C2.
https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors/
