CyberSecurity News
New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
AI summary
A newly discovered Linux toolkit, referred to as ted, has been embedded into compromised HAProxy load balancers at two South Korean organizations. This toolkit intercepts web traffic and serves modified pages to specific visitors. The attackers were able to compile the ted toolkit directly into the HAProxy builds. The presence of ted does not result from a HAProxy vulnerability, but rather from the attackers having achieved code execution on the host. The discovery was made through debug strings left in the binary, which included the name ted. The compromise requires the attackers to have already gained code execution capabilities on the targeted system.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

