Skip to main content
← Back to Demos
Malware intermediate · 15 min

DPRK-Linked 'ted' Backdoor Compiled Into HAProxy Load Balancers (Rapid7) — Trojanized Server Binaries Flagged by Metascan (2026-09-13 CISO Daily Digest)

The 2026-09-13 CISO Daily Digest covered Rapid7's disclosure of a previously undocumented North Korea-linked Linux espionage toolkit whose centerpiece, the 'ted' backdoor, was not dropped alongside HAProxy but compiled directly into a trojanized HAProxy 2.8.12 build at two South Korean organizations in the automotive and media sectors — where it may have operated undetected for nine to ten months. ted is not a separate process: it is compiled into HAProxy's own source as a custom plugin, using the load balancer's native filter API, internal memory pools and event scheduler to intercept traffic while genuine load balancing keeps running normally on top of it. Because a load balancer terminates TLS, the implant could read and modify decrypted traffic for every session passing through it: stealing cookies and credentials, redirecting selected visitors (chosen by IP, URL, referrer and User-Agent) to exploit pages, and running remote commands — while erasing its own entries from HAProxy's connection statistics and logs, timestomping its binary to match /usr/bin/ssh, and deleting lines from auth.log, syslog and audit.log. Rapid7 also found trojanized crond, atd, sshd, polkitd and agetty binaries, an SSH credential logger, and the curl-based curlRAT remote-access tool; command-and-control rides fake image requests on domains such as img.monderhouse[.]space and img.darklights[.]store, blended into Naver's pstatic.net traffic pattern. Attribution sits at medium confidence to DPRK-aligned actors: the targeting pattern, simple XOR-based encryption, a custom substitution cipher and command-server infrastructure already linked to APT37 by other threat-intelligence feeds point toward North Korean state involvement, with technical overlaps also drawing comparisons to a concurrent Lazarus Group campaign against South Korean media. Notably, no HAProxy vulnerability was involved — the attackers replaced the legitimate binary after gaining code execution. This demo ships EICAR test files — a classic eicar.com, an eicar.txt, a compiled Windows PE embedding the EICAR string, and a ZIP-wrapped EICAR — standing in for the trojanized HAProxy build and the tampered system binaries, plus a clean control file (no real malware, nothing destructive). MetaDefender Multiscan runs 30+ engines (including ClamAV) over every variant in one pass and flags them all, showing how tampered server binaries are caught at the file boundary — before a weaponized build like ted ever reaches a production load balancer (MITRE ATT&CK T1554 — Compromise Host Software Binary).

Attack Technique

Trojanized server binaries — the 'ted' backdoor is compiled directly into a modified HAProxy 2.8.12 build (and the stager overwrites crond, atd, sshd, polkitd and agetty), so the implant rides inside a legitimate executable that keeps serving normal traffic and exfiltrates via fake-image-request C2; the demo shows malicious binaries crossing the file boundary as EICAR stand-ins, flagged by multiscanning before execution (T1554 Compromise Host Software Binary)

MITRE ATT&CK

T1554 ↗

Platforms

linux

File Types

.com.exe.txt.zip

MetaDefender Capabilities

Metascan

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---