CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

New Ted Backdoor Hides Inside Victims’ Own HAProxy Builds to Intercept Web Traffic

September 4, 2026

New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic Swati KhandelwalSep 04, 2026Malware / Network Security A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and the ability to replace the running binary. Rapid7 Labs attributed the toolkit with medium confidence to North Korean state-sponsored actors and put the two victims in South Korea's automotive and media sectors. Command-and-control (C2) requests never reach a…