New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
A newly discovered Linux implant dubbed 'Ted' was compiled directly into victims' HAProxy binaries in South Korea, intercepting and altering web traffic — a build-pipeline supply-chain attack that evades conventional file-integrity monitoring.
Summary written by editorial AI · Source link below
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors.
The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and
Editorial Analysis
Framed for the SOC Analyst desk
The 'Ted' backdoor intercepts and modifies live web traffic at the load-balancer layer — a blind spot for most endpoint and network detection stacks.
Deploy binary attestation checks on load-balancer builds and add detection rules for anomalous HAProxy behaviour such as unexpected page content injection.
Attackers embedded malware directly inside a widely used load-balancer's compiled code, a supply-chain technique that could affect any organisation building open-source infrastructure from source.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at THN (Feedburner) in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner1d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d