Interestana
Home/News/New Ted Backdoor Hides Inside HAProxy Builds
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

New Ted Backdoor Hides Inside HAProxy Builds

New Ted Backdoor Hides Inside HAProxy Builds

A sophisticated and previously undocumented Linux toolkit, identified as the 'ted' backdoor, has been discovered embedded directly within trojanized HAProxy load balancer builds. This malicious implant was found targeting two South Korean organizations, where it actively intercepted web traffic and served altered web pages to specific, selected visitors. The attackers themselves named the implant 'ted' within debug strings present in the binary, providing a direct identifier for the malware.

The discovery, detailed in a security advisory, highlights that 'ted' is not exploiting a vulnerability within the HAProxy software itself. Instead, its deployment requires attackers to first achieve code execution on the host system where HAProxy is running. Once on the system, the attackers can then compile their malicious code into the HAProxy binary. This method of integration makes the backdoor exceptionally stealthy, as it resides within a legitimate and essential network service, potentially evading standard security monitoring that focuses on external network traffic or separate malicious processes.

The 'ted' backdoor's primary function is to act as a web traffic interceptor. By embedding itself within HAProxy, it gains the capability to monitor and manipulate HTTP and HTTPS requests and responses passing through the load balancer. This allows the attackers to selectively modify the content delivered to specific users, potentially for phishing, credential harvesting, or distributing further malware. The targeting of South Korean organizations suggests a geographically focused campaign, though the full scope of its operations and the motivations behind these specific attacks remain under investigation by cybersecurity researchers.

HAProxy is a widely used open-source software that provides high-availability load balancing and proxying for TCP and HTTP-based applications. Its role in managing and directing network traffic makes it a critical component for many web services. By compromising HAProxy builds, attackers can gain a powerful vantage point within an organization's network infrastructure. The 'ted' backdoor's design, which involves compiling directly into the HAProxy binary, represents an advanced technique that bypasses traditional detection methods. Security professionals are advising organizations using HAProxy to rigorously verify the integrity of their HAProxy installations and to monitor for any unusual modifications or unexpected behavior in their network traffic and server processes. Further analysis is ongoing to understand the full capabilities of the 'ted' backdoor and to develop effective countermeasures against this novel threat.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next