North Korean 'Ted' Backdoor Trojanizes HAProxy Load
A North Korean toolkit named 'Ted' has been found compiled into trojanized HAProxy load balancers at two South Korean firms, intercepting web traffic and

A previously undocumented Linux toolkit has been compiled directly into the trojanized HAProxy load balancers of two South Korean organizations. The implant, named 'Ted' in its debug strings, intercepted web traffic and served modified pages to selected visitors.
Rapid7 attributed the toolkit with medium confidence to North Korean state-sponsored actors. The two identified victims are in South Korea's automotive and media sectors. The security firm stated that further evidence is necessary for a more definitive assessment.
How the Ted Backdoor Operates
The Ted implant is not a vulnerability in HAProxy itself. Installing it requires an attacker to already have code execution on the host and the ability to replace the running binary. The backdoor is triggered when a request is made for one specific image path, putting it into command-and-control (C2) mode.
When activated, the implant decrements HAProxy's live connection counters, effectively erasing the C2 request from the load balancer's statistics. It writes the command body to a named pipe under /tmp and zeroes the request channel, so nothing is forwarded to a backend server. Command output is returned on the raw socket under a standard HTTP/1.0 200 OK header, making the exchange appear as ordinary web traffic.
Through this channel, an operator can example, upload and download files, run shell commands, and replace the implant's configuration.
Selective Traffic Interception
The backdoor only modifies pages for requests that pass four specific checks. The request must carry a User-Agent and match a rule where both the URL and referer patterns fit. Delivery then depends on either whitelist membership of the client IP address, checked exactly and again at the /24 subnet level, or an operator key placed in the Accept-Language header which overrides the address filtering entirely.
On the way out, the implant rewrites the content type and length, forces the response status to 200, and deletes the Accept-Ranges header. This last step prevents a client from requesting byte ranges and noticing the changed size of the content.
Deployment and Evasion Techniques
Rapid7's evidence was not enough to establish a timeline or determine initial access. However, the firm presented a hypothesis, citing ENKI research, that attackers may have entered through an exposed Groupware portal, a class of Korean enterprise collaboration software previously compromised by the Kimsuky group.
The stager only deploys where HAProxy or the cron scheduler is already running, and it verifies root privileges before dropping anything. It overwrites the legitimate crond binary, giving the replacement the creation timestamp of /usr/bin/ssh. It then strips keywords like tmp, wget, cron, and crond from root's bash history and from six system logs, including auth.log and audit/audit.log.
The same toolkit includes a trojanized sshd binary that encrypts captured plaintext passwords to a fixed path. Rapid7 also found the same malicious code in trojanized agetty, atd, and polkitd binaries. A companion remote access trojan (RAT), which Rapid7 calls curlRAT, beacons every 12 hours by default, dropping to a 30-second interval when an operator sets a flag. It aborts unless it finds a marker file indicating the host is virtualized.
Attribution and Infrastructure
Rapid7's attribution draws on three separate North Korean clusters: APT37 for domain infrastructure, Lazarus for the delivery model, and Kimsuky for the initial-access hypothesis. Mandiant's 2023 assessment noted shared tooling and overlapping targeting across these clusters, stating, "We believe that this will make precise attribution more difficult."
The firm shared several indicators of compromise (IoCs), including six domains and multiple file hashes. The Hacker News confirmed on September 4 that none of the six domains currently resolve. They are present in the maltrail open-source detection project's data, labelled as APT37 infrastructure based on two X posts from July 2025.
Vulnerable Software and Mitigation
Both victim organizations were running HAProxy version 2.8.12, released on November 8, 2024. The implant reads HAProxy's internal structures at offsets fixed to that specific release. The current release on that branch is 2.8.28, from August 27, 2026. HAProxy's bug tracker lists 529 known bugs affecting version 2.8.12 that are already fixed in the branch.
| HAProxy Version | Release Date | Known Bugs in 2.8.12 Fixed in Branch |
|---|---|---|
| 2.8.12 | November 8, 2024 | 529 (1 critical, 16 major) |
| 2.8.28 | August 27, 2026 | (All fixes included) |
Upgrading HAProxy does not clean a host already compromised by Ted, as the attackers replace the binary rather than exploit a flaw in it. Rapid7 recommended independent network correlation, memory behavioural analysis, and binary integrity checks. A recompiled, malicious HAProxy binary reports the same version string as a clean build.
The development follows a similar watering-hole campaign documented in July by AhnLab and ENKI WhiteHat, where state-sponsored operators abused compromised Korean websites to attack the AnySign4PC signing client.





