Trojanized HAProxy Builds Used to Hijack Web Traffic in South Korea
Security researchers have uncovered a previously undocumented Linux implant, dubbed 'Ted' after debug strings found in the code, hidden inside custom-compiled versions of the popular HAProxy load balancer. The backdoor was found at two South Korean organisations, where it intercepted web traffic passing through the compromised servers and served altered content to selected visitors.
Importantly, this is not a flaw in HAProxy itself. Attackers first needed to gain code execution on the target systems before rebuilding HAProxy with the malicious implant baked in, meaning the load balancer's normal functions continued to work while quietly enabling traffic manipulation behind the scenes. This approach makes the compromise harder to spot, since the malicious code is embedded in what looks like a legitimate, custom-built software component rather than a separate suspicious file.
The discovery highlights a growing trend of attackers targeting trusted infrastructure components, such as load balancers and reverse proxies, to gain persistent access and manipulate traffic without raising immediate alarms. Businesses that rely on custom-built or self-compiled network software should be aware that such tools can be tampered with if attackers first gain a foothold on the server.