AUTO-UPDATED

North Korea-linked Hackers Hide a Backdoor Inside HAProxy

North Korean-linked hackers are compromising South Korean automotive and media firms by embedding a sophisticated "ted backdoor" directly into the source code of HAProxy load balancing software.

Key Points

  • Researchers at Rapid7 identified a Linux toolkit that integrates malicious code into HAProxy version 2.8.12 using its native filter API.
  • The backdoor intercepts HTTP traffic and executes remote commands by triggering a hidden mode via requests for a specific fake image file.
  • Malicious activity is erased from internal logs and statistics, allowing the malware to perform credential harvesting and surveillance without leaving a trace.
  • The campaign also deploys trojanized versions of standard Linux daemons, including crond, agetty, and sshd, to maintain persistence and log administrator passwords.
  • Evidence, including infrastructure and encryption methods, suggests the involvement of North Korean state-sponsored actors, potentially linked to APT37 or the Lazarus Group.

Why it Matters

This attack demonstrates a shift toward deep-level infrastructure compromise where malicious code is woven into essential network components rather than running as separate processes. Organizations must now implement independent binary integrity checks and memory behavioral analysis, as relying on standard application logs is no longer sufficient to detect sophisticated edge-based threats.
Securityaffairs.com Published by Pierluigi Paganini
Read original