hacker-news · Crawled Sep 4, 2026

New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

12 IoCs 2 Actors
Read original article ↗

AI Summary

A previously undocumented Linux backdoor named 'ted' has been discovered embedded within trojanized HAProxy binaries deployed at two South Korean organizations in the automotive and media sectors. The implant intercepts web traffic, enables command-and-control (C2) communication by mimicking legitimate HTTP responses, and allows attackers to execute shell commands, upload/download files, and modify configurations. Rapid7 Labs attributes the activity with medium confidence to North Korean state-sponsored actors, potentially linked to APT37, Lazarus, and Kimsuky clusters, based on infrastructure overlaps and operational patterns. The backdoor evades logging by manipulating HAProxy's internal connection counters and uses trojanized system binaries such as crond, sshd, agetty, atd, and polkitd to maintain persistence and exfiltrate credentials.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 12 extracted

Type Value Detail
Domain img[.]monderhouse[.]space Details →
Domain img[.]smartnords[.]site Details →
Domain img[.]darklights[.]store Details →
Domain img[.]responsive[.]pstatic[.]autos Details →
Domain img[.]socialteams[.]store Details →
Domain img[.]worksongo[.]store Details →
Filename ~/cache/haproxy-1000.cache Details →
Filename /var/lib/sshd/c8c68e629bba773a10ac80012d10bf19 Details →
Filename /var/lib/snapd/g580 Details →
Filename /tmp/jasper-log Details →
SHA-256 72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558 Details →
SHA-256 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5 Details →

MITRE ATT&CK TTPs 8 techniques