Discussion

New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

Started by The Hacker News · 04 Sep 2026 18:10 · 1 Views · 0 Replies
Thread Starter #0
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors.

The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and

Okumaya devam et...

You must be logged in to reply.

Users who are viewing this thread (Total: 1, Members: 1, Guests: 0)
Total: 1 (members: 1, guests: 0)
0 quotes selected