New Ted Backdoor Exploits HAProxy to Intercept Web Traffic in South Korean Organizations
A new backdoor named 'Ted' has been discovered embedded within HAProxy load balancers of South Korean organizations, enabling attackers to intercept web traffic and manipulate responses without detection. The malware, linked to North Korean state-sponsored actors, uses covert command-and-control channels and evades logging by modifying HAProxy's internal structures.
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors.
The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and
*** END OF TRANSMISSION ***