New Ted Backdoor Hides Inside Victims’ Own HAProxy Builds to Intercept Web Traffic

A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors.

The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

AI changes the economics of software rewrites

AI changes the economics of software rewrites Source: Hacker News

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze

Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths

Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting