$ techbeacon▋
Phishing

North Korean Hackers Embed Stealth Backdoor in HAProxy Load Balancer Code

North Korean Hackers Embed Stealth Backdoor in HAProxy Load Balancer Code

Security researchers have uncovered a sophisticated backdoor hidden directly in the source code of HAProxy, the open‑source load‑balancing software that powers millions of web services worldwide. The malicious code allows threat actors to route command‑and‑control traffic and siphon data while the affected proxy continues to operate normally, making detection extremely difficult.

HAProxy is widely deployed to distribute incoming network requests across multiple servers, ensuring high availability and performance for everything from e‑commerce sites to critical infrastructure. Because it sits at the front line of traffic, compromising the software can give attackers a privileged view of user interactions and internal communications.

According to the investigation, the malicious payload was inserted into the HAProxy codebase itself, not as an external plugin or script. By embedding the backdoor within core functions that handle packet forwarding, the attackers ensured that the malicious logic would be compiled into the binary alongside legitimate features, evading typical file‑integrity checks.

The hidden module establishes an encrypted channel to a remote server, disguising its traffic as ordinary HAProxy communications. At the same time, it quietly copies sensitive payloads—such as authentication tokens and user data—to the attacker’s infrastructure. Because the load balancer continues to forward legitimate requests, the compromise often goes unnoticed until a thorough code audit is performed.

Cyber‑security analysts have linked the technique to a group with known ties to North Korea, citing similarities to previous operations that targeted VPNs and container orchestration tools. The group has a history of embedding malicious code in widely used open‑source projects to achieve large‑scale footholds without needing to breach individual organizations directly.

Following the disclosure, the HAProxy maintainers issued an emergency advisory, urging administrators to verify the integrity of their installations against the official repository and to apply the latest patches that remove the rogue code. The project’s developers also announced a review of the contribution workflow to tighten vetting of external contributions.

The episode underscores the growing risk of supply‑chain attacks on critical internet infrastructure. Experts warn that as more organizations rely on open‑source components, rigorous verification and continuous monitoring will become essential safeguards against covert infiltration by state‑backed actors.

Mahesh Kumar Sahoo — Mahesh covers ransomware gangs, data leak sites, and dark web marketplaces, mapping how stolen data surfaces and gets sold. Follows ShinyHunters-style groups across leak forums.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related