
highMalware
Trojanized HAProxy Load Balancers Deploy Previously Undocumented 'ted' Backdoor in South Korea
Security researchers have identified a previously undocumented Linux toolkit embedded into trojanized HAProxy load balancers used by two organizations in South Korea. The implant, internally named 'ted' after debug strings found in the binary, intercepts web traffic and serves altered pages to selected visitors. The attack does not exploit a vulnerability in HAProxy itself; instead, it requires code execution on the host to install the compromised binary, indicating a supply-chain or insider threat vector.
The Hacker News2 min read