Hidden Trojan Embedded in HAProxy Load Balancers Used by South Korean Firms to Manipulate Web Traffic
Security analysts have uncovered a previously unknown Linux toolkit, internally named "ted," that was compiled directly into compromised HAProxy load balancer binaries deployed by two organisations in South Korea. The malicious component allowed the attackers to intercept inbound web requests and serve altered content to selected visitors, effectively turning the load balancer into a man‑in‑the‑middle device.
HAProxy is a widely adopted, open‑source reverse proxy and load‑balancing solution that sits at the front of web infrastructure, directing traffic to backend servers while handling high volumes of concurrent connections. Because it processes every request before it reaches the application layer, compromising HAProxy gives an adversary a privileged position to monitor, modify, or block traffic without raising immediate suspicion.
The "ted" implant was linked to the HAProxy executable itself, meaning the malicious code executed as part of the normal load‑balancing process. Researchers observed that the toolkit intercepted HTTP traffic, examined request attributes, and then delivered counterfeit pages to specific users based on criteria such as IP address or URL path. The altered pages were designed to appear legitimate, suggesting a targeted information‑stealing or credential‑harvesting campaign rather than a broad defacement effort.
The discovery emerged during a routine audit of network assets when analysts noticed anomalous debug strings embedded in the HAProxy binary. The string "ted" appeared in the compiled code, prompting deeper reverse‑engineering that revealed the full backdoor functionality. To date, the toolkit has not been documented in any public malware repository, indicating that the attackers may have developed it in‑house or obtained it from a private source.
Experts warn that the incident highlights the growing risk of supply‑chain attacks on critical infrastructure components. Organizations are urged to verify the integrity of third‑party binaries, apply strict version control, and monitor runtime behavior for unexpected network activity. Further investigation is underway to determine the extent of the compromise, the identity of the threat actors, and whether additional HAProxy instances elsewhere may be affected.
Comments (0)
Be the first to comment.
Join the discussion