Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Ted Backdoor Found in HAProxy Systems

New Ted Backdoor Found in HAProxy Systems

Posted on September 4, 2026 By CWS

A newly identified Linux malware, known as the Ted backdoor, has emerged within the compromised HAProxy load balancers of two South Korean entities. This backdoor, strategically embedded by attackers, intercepts web traffic to deliver manipulated web pages to specific users. The malware’s presence was uncovered by cybersecurity researchers at Rapid7, who have linked it with medium confidence to North Korean state-sponsored groups targeting South Korea’s automotive and media sectors.

Technical Insights into the Ted Backdoor

The Ted implant is cleverly named within the code, but it should not be misconstrued as a vulnerability in HAProxy itself. Instead, its installation demands unauthorized code execution on the host system and substitution of the HAProxy binary. This malware’s actions are stealthy, as it manages to erase command-and-control (C2) requests from the load balancer’s logs, leaving no trace in HAProxy’s connection statistics.

The backdoor operates by entering a specialized mode upon receiving a particular image path request. This action causes the load balancer to drop the connection from its statistics and write the command body to a temporary location. The response mimics regular web traffic, using a standard HTTP/1.0 200 OK header, allowing the attacker to perform various malicious activities including file transfers and remote command execution.

Implications and Attribution

Rapid7’s analysis indicates that the attackers possibly exploited a Groupware portal vulnerability for initial access, aligning with past reports of North Korean group Kimsuky targeting similar systems. The implant alters outgoing data by modifying content type and length, forcing a 200 status response, and removing headers that could reveal size discrepancies.

Rapid7 has not yet established a timeline for the attack or confirmed the initial entry method. However, the use of a trojanized sshd and other binaries like agetty and polkitd, along with a remote access trojan dubbed curlRAT, suggests a sophisticated operation. Indicators of compromise (IoCs) include several domain names and file paths, which, as of September 4, were no longer active.

Security Recommendations and Future Outlook

To mitigate the risk posed by the Ted backdoor, Rapid7 recommends rigorous network correlation, memory behavior analysis, and integrity checks of binaries. Although no specific detection rules were provided, these steps are crucial for identifying and neutralizing the threat. Furthermore, the continuous evolution of HAProxy versions suggests that upgrading alone will not remove the backdoor if already present.

As cybersecurity threats continue to evolve, organizations must remain vigilant and proactive in securing their infrastructure. The Ted backdoor serves as a stark reminder of the persistent and sophisticated tactics employed by state-sponsored actors, underscoring the need for comprehensive security measures and constant monitoring.

The Hacker News Tags:APT37, backdoor implant, command-and-control, cyber threat, Cybersecurity, HAProxy, Kimsuky, Lazarus, Linux toolkit, Malware, network security, North Korea, Rapid7, Ted backdoor, web traffic interception

Post navigation

Previous Post: Hackers Exploit AI Models for Cyberattacks in Asia
Next Post: Critical Flaws in VMware Workstation and Fusion Addressed

Related Posts

Notepad++ Secures Update Process Against Malware Threat Notepad++ Secures Update Process Against Malware Threat The Hacker News
Flying Eagle Android RAT Found on 170 Servers Flying Eagle Android RAT Found on 170 Servers The Hacker News
AI’s Impact on Software Supply Chain Security AI’s Impact on Software Supply Chain Security The Hacker News
Researchers Find VS Code Flaw Allowing Attackers to Republish Deleted Extensions Under Same Names Researchers Find VS Code Flaw Allowing Attackers to Republish Deleted Extensions Under Same Names The Hacker News
Hackers Used Snappybee Malware and Citrix Flaw to Breach European Telecom Network Hackers Used Snappybee Malware and Citrix Flaw to Breach European Telecom Network The Hacker News
New ClayRat Spyware Targets Android Users via Fake WhatsApp and TikTok Apps New ClayRat Spyware Targets Android Users via Fake WhatsApp and TikTok Apps The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026
  • Hackers Exploit Unicode to Bypass Phishing Filters
  • OpenAI Allocates $1 Billion to Support Cybersecurity
  • Microsoft Launches Project Zenith for Local AI Model Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026
  • Hackers Exploit Unicode to Bypass Phishing Filters
  • OpenAI Allocates $1 Billion to Support Cybersecurity
  • Microsoft Launches Project Zenith for Local AI Model Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark