<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic]]></title><description><![CDATA[<p dir="auto">A newly identified Linux backdoor, named <strong>ted</strong> in debug strings left by its developers, was found compiled directly into trojanized builds of <strong>HAProxy</strong> on systems belonging to two South Korean organizations. The implant did not exploit any vulnerability in HAProxy itself; the attackers had already achieved code execution on the target hosts and chose this stealthy persistence method to blend in with legitimate network infrastructure.</p>
<p dir="auto">Once active, <strong>ted</strong> intercepted incoming web traffic passing through the compromised load balancers. Instead of simply monitoring data, it selectively served altered web pages to chosen visitors, suggesting a highly targeted operation aimed at delivering modified content or credentials-harvesting pages to specific users. The use of trojanized HAProxy builds is notable because it allows malicious code to evade detection by masquerading as a trusted, frequently updated system component.</p>
<p dir="auto">This discovery highlights a growing trend of threat actors abusing open-source software supply chains at the deployment stage. By embedding malicious code directly into a commonly used network tool, the attackers ensured their backdoor survived reboots and software updates, and remained invisible to traditional file-scanning solutions.</p>
<p dir="auto">Key technical details:</p>
<ul>
<li>Implant name: <strong>ted</strong>, found in debug strings.</li>
<li>Delivery method: Compiled into HAProxy binaries, not a HAProxy vulnerability.</li>
<li>Prerequisite for installation: Prior code execution on the host.</li>
<li>Observed behavior: Interception of web traffic and serving of altered pages to targeted visitors.</li>
<li>Victims: Two organizations based in South Korea.</li>
</ul>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/new-ted-backdoor-hides-inside-victims.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Given that this backdoor was compiled directly into HAProxy, how is your organization verifying the integrity of open-source binaries in production, especially those handling sensitive traffic?</p>
]]></description><link>https://xploitlk.com/topic/220/new-ted-backdoor-hides-inside-victims-own-haproxy-builds-to-intercept-web-traffic</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 12:37:44 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/220.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 05 Sep 2026 02:30:24 GMT</pubDate><ttl>60</ttl></channel></rss>