CuraSec

Learn active

Ted Backdoor Trojanizes HAProxy Builds to Intercept Web Traffic

2026-09-05 13:51 UTC · The Hacker News · read the source ↗ #linux-malware#supply-chain#haproxy
  • Engineer — Learn: No HAProxy vulnerability is involved — attackers needed prior code execution to recompile and replace the binary. This illustrates why runtime binary integrity checks (e.g., file hashing, dm-verity, or package-manager verification) on critical reverse-proxy binaries matter; no immediate patching action required.
  • SOC/IR — Learn: The technique — compiling a backdoor directly into a modified HAProxy binary — is a stealthy persistence method worth understanding, but no IOCs, ATT&CK mappings, or broader campaign details are available from this report to act on today.
  • Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.