Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageThreat Intel Desk
Threat Intel

New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

A newly discovered Linux implant dubbed 'Ted' was compiled directly into victims' HAProxy binaries in South Korea, intercepting and altering web traffic — a build-pipeline supply-chain attack that evades conventional file-integrity monitoring.

Summary written by editorial AI · Source link below

Filed by THN (Feedburner)1 min readRead at source ↗

A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors.

The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and

Editorial Analysis

Framed for the CISO & Security Leaders desk

Why it matters

A supply-chain implant compiled directly into production HAProxy binaries represents a stealthy, persistent compromise vector that bypasses traditional file-integrity checks on config files.

What to do

Commission an audit of all self-compiled or vendor-supplied load-balancer binaries against known-good hashes.

Board brief

Attackers embedded malware directly inside a widely used load-balancer's compiled code, a supply-chain technique that could affect any organisation building open-source infrastructure from source.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at THN (Feedburner)

External link — opens at THN (Feedburner) in a new tab.

§
Continue with

More from the Threat Intel Desk