{"id":1404,"date":"2026-09-07T11:39:59","date_gmt":"2026-09-07T06:09:59","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1404"},"modified":"2026-09-08T11:05:43","modified_gmt":"2026-09-08T05:35:43","slug":"ted-backdoor-hijacks-haproxy-to-intercept-web-traffic","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\/","title":{"rendered":"Ted Backdoor Hijacks HAProxy to Intercept Web Traffic"},"content":{"rendered":"<p>Rapid7 Labs disclosed a Linux toolkit hidden inside a victim&#8217;s load balancer software. The researchers named the implant the Ted backdoor, based on debug strings left in the binary. Attackers compiled the Ted backdoor directly into trojanized HAProxy builds running at two South Korean organizations, one in the automotive sector and one in media.<\/p>\n<p>The implant does not exploit a flaw in HAProxy&#8217;s code. Instead, the operators needed code execution on the host first, then replaced the running HAProxy binary with their own build. Once in place, the implant intercepted web traffic passing through the load balancer and served altered pages to specific visitors, all while genuine traffic kept flowing normally.<\/p>\n<p>Rapid7 attributed the campaign with medium confidence to North Korean state-sponsored activity, citing infrastructure overlaps with APT37 tracked by ThreatFox and Maltrail. The firm also found this implant sitting alongside a wider toolkit built for long-term access and <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-credential-stealer\/\">credential theft<\/a>.<\/p>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tBook a free demo and explore Hexnode today!<\/a>\r\n    \t\t<\/center><\/p>\n<h2>What the Ted Backdoor actually does inside HAProxy<\/h2>\n<p>The Ted backdoor does not run as a separate process next to HAProxy. Attackers built it directly into the load balancer&#8217;s own code. It reuses HAProxy&#8217;s native filter API, memory pools, event scheduler, and process management infrastructure to operate.<\/p>\n<h3>This design gives the implant several capabilities:<\/h3>\n<ul>\n<li>A request to one specific image path, such as <code>\/favorite_list_2x_m500_ico.jpg<\/code>, switches the implant into command mode.<\/li>\n<li>Once in command mode, it can beacon to command infrastructure, upload and download files, execute shell commands, and rewrite its own configuration.<\/li>\n<li>For web injection, it matches incoming requests against operator-defined regex rules covering the User-Agent, URL, and Referer values before deciding whether to serve altered content.<\/li>\n<li>A separate header-based operator key can override client-address whitelisting, so a visitor without whitelisted access can still receive the modified page.<\/li>\n<li>It serves altered pages only to selected visitors, keeping the campaign narrow and harder to spot.<\/li>\n<\/ul>\n<p>Because the Ted backdoor lives inside a trusted, already-running process, standard endpoint tools that watch for new or unusual binaries can miss it entirely.<\/p>\n<h2>Why backend logs miss the Ted Backdoor&#8217;s traffic<\/h2>\n<p>HAProxy normally sits between users and backend applications, forwarding requests and logging what passes through. The Ted backdoor breaks that assumption. It intercepts and answers <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-command-and-control-c2\/\">command-and-control<\/a> requests at the load balancer layer itself, so those requests never reach the backend servers.<\/p>\n<p>Backend web-server logs and application logs stay clean. Counters that track normal traffic volume exclude the C2 requests entirely. A security team reviewing only backend telemetry would see nothing unusual, even while the Ted backdoor actively communicates with its operators.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-challenges.jpeg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Top 10 Cybersecurity Challenges for Enterprises<\/h4><p>Top 10 enterprise cybersecurity challenges, risks, and Hexnode's mitigation strategies.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/top-10-cybersecurity-challenges-for-enterprises\/\" aria-label=\"Top 10 Cybersecurity Challenges for Enterprises\"><\/a><\/div><\/div><\/div>\n<h2>The rest of the toolkit: curlRAT, a Stager, and an SSH Keylogger<\/h2>\n<p>Rapid7 found the Ted backdoor operating alongside several other trojanized components on the same hosts:<\/p>\n<ul>\n<li>curlRAT, a curl-based remote access <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-trojan\/\">trojan<\/a> that runs a watchdog thread to monitor HAProxy&#8217;s health and report status back to the operators.<\/li>\n<li>A stager, built from a trojanized crond binary, that deploys only where HAProxy or cron already runs and checks for root privileges before dropping anything. Rapid7 found the same trojanizing code in additional system service binaries, including agetty, atd, and polkitd, extending the toolkit&#8217;s footprint well beyond the load balancer itself.<\/li>\n<li>A trojanized SSH daemon that captures plaintext credentials, encrypts them, and writes them to a fixed path on disk.<\/li>\n<\/ul>\n<p>The stager also covers its tracks. It gives its replacement crond binary the file creation timestamp of the legitimate ssh binary, then strips keywords tied to its own deployment from root&#8217;s bash history and from several system logs, including authentication and audit logs.<\/p>\n<p>Rapid7&#8217;s earliest VirusTotal samples date to mid-2025, though the HAProxy 2.8.12 build the toolkit trojanizes shipped in November 2024, setting the earliest possible compilation window.<\/p>\n<h2>Ted Backdoor toolkit components<\/h2>\n<table style=\"width: 100%;\">\n<thead>\n<tr>\n<th style=\"width: 23.6787%; text-align: left;\">Component<\/th>\n<th style=\"width: 37.2092%; text-align: left;\">Function<\/th>\n<th style=\"width: 37.9493%; text-align: left;\">Operational Risk<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width: 23.6787%;\">Ted backdoor (HAProxy)<\/td>\n<td style=\"width: 37.2092%;\">Intercepts web traffic, serves altered content, executes commands<\/td>\n<td style=\"width: 37.9493%;\">High \u2014 embedded in trusted, always-running infrastructure<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 23.6787%;\">curlRAT<\/td>\n<td style=\"width: 37.2092%;\">Curl-based RAT that monitors implant health and reports to operators<\/td>\n<td style=\"width: 37.9493%;\">Medium \u2014 persistent secondary C2 channel<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 23.6787%;\">Trojanized SSH daemon<\/td>\n<td style=\"width: 37.2092%;\">Captures and encrypts plaintext login credentials<\/td>\n<td style=\"width: 37.9493%;\">High \u2014 direct credential theft<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 23.6787%;\">Stager (trojanized crond,agetty, atd, polkitd)<\/td>\n<td style=\"width: 37.2092%;\">Deploys payloads and erases log and history traces<\/td>\n<td style=\"width: 37.9493%;\">High \u2014 undermines forensic investigation<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Attribution and the open access question<\/h2>\n<p>Rapid7 built its medium-confidence North Korean attribution on three separate clusters: APT37 infrastructure overlaps tracked by ThreatFox and Maltrail, a delivery model resembling the Lazarus-linked Operation SyncHole campaign, and an initial-access hypothesis tied to Kimsuky.<\/p>\n<p>Rapid7 did not confirm how the attackers first gained access. The firm raised a hypothesis, based on separate ENKI research documenting a Kimsuky compromise of a Korean groupware vendor, that an exposed Groupware portal, a category of Korean enterprise collaboration software, may have provided the initial foothold.<\/p>\n<p>Rapid7 presented this as a hypothesis, not a confirmed finding, and the firm could not build a full intrusion timeline from the available evidence.<\/p>\n<h2>What security teams should check now?<\/h2>\n<ul>\n<li>Standard vulnerability scanners and patch deployment tools will report HAProxy 2.8.12 as up to date, since the version string matches a legitimate release. Version checks alone will not catch this implant.<\/li>\n<li>Run cryptographic hash verification, such as SHA-256, against clean vendor-provided binaries for the deployed version, rather than relying on version-string checks.<\/li>\n<li>Deploy file integrity monitoring on Linux edge servers running load balancers, so any unauthorized binary replacement triggers an alert.<\/li>\n<li>Search for anomalous debug strings or unexpected filter modules compiled into production builds.<\/li>\n<li>Review authentication and audit logs for gaps or signs of tampering, not just their contents.<\/li>\n<li>Confirm administrator endpoints used to manage load balancers carry current security updates. Server patching and <a href=\"https:\/\/www.hexnode.com\/blogs\/it-admins-guide-to-patch-management-with-hexnode\/\">endpoint patch hygiene<\/a> are separate controls.<\/li>\n<li>Extend monitoring beyond backend application logs to cover the load balancer layer itself.<\/li>\n<\/ul>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-.jpg?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity kit\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-.jpg?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--300x225.jpg?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--768x576.jpg?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--133x100.jpg?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity kit\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Cybersecurity kit\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Free cybersecurity kit: blueprint, framework guide, IT checklist, incident policy template, UEM infographic, and management guides.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/resource-kits\/cybersecurity-kit\/'>\n                            DOWNLOAD\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Is the Ted backdoor a HAProxy vulnerability that needs a patch?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>No. Rapid7 described it as a trojanized build, not a flaw in HAProxy&#8217;s official code. Attackers still needed prior code execution and the ability to replace the running binary.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">How would a team notice a Ted backdoor infection given clean backend logs?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Backend logs will not show it, since command-and-control traffic never reaches them. Teams need binary integrity checks against known-good HAProxy hashes and closer review of the load balancer host itself.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Does removing the Ted backdoor fully remove the threat?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Not on its own. Rapid7 found a broader toolkit on the same hosts, including curlRAT, a trojanized SSH daemon, and a stager, so a full host review matters beyond just the HAProxy binary.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n<h3>Conclusion<\/h3>\n<p>The Ted backdoor shows how attackers can turn trusted traffic infrastructure into a blind spot once they gain a foothold on the host. By compiling directly into HAProxy, the Ted backdoor intercepts traffic and hides its command-and-control activity from the logs security teams check first.<\/p>\n<p>Organizations running HAProxy or similar load balancers should verify binary integrity, extend monitoring beyond backend logs, and treat administrator access to traffic infrastructure as a priority control point, not an afterthought.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Hidden in your load balancer? Check now.<\/h5><p>Get security briefings like this one, straight to your inbox.<\/p><a href=\"https:\/\/www.hexnode.com\/xdr\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> SIGN UP NOW<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Rapid7 Labs disclosed a Linux toolkit hidden inside a victim&#8217;s load balancer software. The researchers&#8230;<\/p>\n","protected":false},"author":5,"featured_media":1427,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13,15],"class_list":["post-1404","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity-abuse","category-malware","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Ted Backdoor: Trojanized HAProxy Intercepts Web Traffic<\/title>\n<meta name=\"description\" content=\"Rapid7 found the Ted backdoor compiled into trojanized HAProxy builds, tied with medium confidence to North Korean cyber espionage.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Ted Backdoor: Trojanized HAProxy Intercepts Web Traffic\" \/>\n<meta property=\"og:description\" content=\"Rapid7 found the Ted backdoor compiled into trojanized HAProxy builds, tied with medium confidence to North Korean cyber espionage.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-07T06:09:59+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-08T05:35:43+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/ted-backdoor.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sophia Hart\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sophia Hart\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\\\/\"},\"author\":{\"name\":\"Sophia Hart\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\"},\"headline\":\"Ted Backdoor Hijacks HAProxy to Intercept Web Traffic\",\"datePublished\":\"2026-09-07T06:09:59+00:00\",\"dateModified\":\"2026-09-08T05:35:43+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\\\/\"},\"wordCount\":1219,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ted-backdoor.jpeg?format=webp\",\"articleSection\":[\"Identity Abuse\",\"Malware\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\\\/\",\"name\":\"Ted Backdoor: Trojanized HAProxy Intercepts Web Traffic\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ted-backdoor.jpeg?format=webp\",\"datePublished\":\"2026-09-07T06:09:59+00:00\",\"dateModified\":\"2026-09-08T05:35:43+00:00\",\"description\":\"Rapid7 found the Ted backdoor compiled into trojanized HAProxy builds, tied with medium confidence to North Korean cyber espionage.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ted-backdoor.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ted-backdoor.jpeg?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"ted backdoor\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Ted Backdoor Hijacks HAProxy to Intercept Web Traffic\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\",\"name\":\"Sophia Hart\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"caption\":\"Sophia Hart\"},\"description\":\"A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions\u2014without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable\u2014politely.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/sophia-hart\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Ted Backdoor: Trojanized HAProxy Intercepts Web Traffic","description":"Rapid7 found the Ted backdoor compiled into trojanized HAProxy builds, tied with medium confidence to North Korean cyber espionage.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\/","og_locale":"en_US","og_type":"article","og_title":"Ted Backdoor: Trojanized HAProxy Intercepts Web Traffic","og_description":"Rapid7 found the Ted backdoor compiled into trojanized HAProxy builds, tied with medium confidence to North Korean cyber espionage.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-07T06:09:59+00:00","article_modified_time":"2026-09-08T05:35:43+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/ted-backdoor.jpeg?format=webp","type":"image\/jpeg"}],"author":"Sophia Hart","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Sophia Hart","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\/"},"author":{"name":"Sophia Hart","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430"},"headline":"Ted Backdoor Hijacks HAProxy to Intercept Web Traffic","datePublished":"2026-09-07T06:09:59+00:00","dateModified":"2026-09-08T05:35:43+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\/"},"wordCount":1219,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/ted-backdoor.jpeg?format=webp","articleSection":["Identity Abuse","Malware"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\/","url":"https:\/\/www.hexnode.com\/threat-watch\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\/","name":"Ted Backdoor: Trojanized HAProxy Intercepts Web Traffic","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/ted-backdoor.jpeg?format=webp","datePublished":"2026-09-07T06:09:59+00:00","dateModified":"2026-09-08T05:35:43+00:00","description":"Rapid7 found the Ted backdoor compiled into trojanized HAProxy builds, tied with medium confidence to North Korean cyber espionage.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/ted-backdoor.jpeg?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/ted-backdoor.jpeg?format=webp","width":1340,"height":700,"caption":"ted backdoor"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/ted-backdoor-hijacks-haproxy-to-intercept-web-traffic\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Ted Backdoor Hijacks HAProxy to Intercept Web Traffic"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430","name":"Sophia Hart","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","caption":"Sophia Hart"},"description":"A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions\u2014without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable\u2014politely.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/sophia-hart\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1404","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1404"}],"version-history":[{"count":5,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1404\/revisions"}],"predecessor-version":[{"id":1459,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1404\/revisions\/1459"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1427"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1404"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1404"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}