New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
Overview
A new Linux toolkit, dubbed 'ted', has been discovered embedded within altered HAProxy load balancers used by two South Korean organizations. This malicious implant allows attackers to intercept web traffic and manipulate the pages seen by certain visitors. The presence of 'ted' in the HAProxy binaries indicates that it does not exploit a vulnerability in HAProxy itself; instead, it requires the attackers to execute code on the affected systems. This incident raises significant concerns as it demonstrates how attackers can compromise widely used software to conduct web traffic interception. Organizations using HAProxy should be vigilant and ensure their installations are secure to prevent such intrusions.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: HAProxy load balancers, South Korean organizations
- Action Required: Organizations should review and secure their HAProxy installations, ensuring only trusted code is executed on their systems.
- Timeline: Newly disclosed
Original Article Summary
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and
Impact
HAProxy load balancers, South Korean organizations
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Organizations should review and secure their HAProxy installations, ensuring only trusted code is executed on their systems.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Linux, Exploit, Vulnerability, and 1 more.