DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

Reported 04 Sep 2026 by otx · Severity: medium

A previously undocumented Linux toolkit has been targeting South Korean automotive and media organizations with minimal detection since early 2025. The campaign employs a HAProxy instance called ted backdoor, compiled within the victim's existing HAProxy version 2.8.12, alongside