New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

Summary

A new Linux backdoor, named 'ted', has been discovered compiled into trojanized HAProxy load balancers at two South Korean organizations. This backdoor intercepts web traffic and serves modified pages to specific users. The attackers required code execution on the host to install this backdoor, indicating it's not a vulnerability within HAProxy itself.

IFF Assessment

FOE

The discovery of a new backdoor that intercepts web traffic and modifies content for victims represents a direct threat to the security and integrity of their online communications and services.

Defender Context

This discovery highlights the sophistication of supply chain attacks where legitimate software is compromised to deliver malware. Defenders should be vigilant about verifying the integrity of their deployed software, especially critical infrastructure like load balancers, and implement robust monitoring for anomalous network traffic and content manipulation.

Read Full Story →