Ted Linux implant in trojanized HAProxy load balancers
Malware Activity
Summary
Hide ▲
Show ▼
The newly identified ted Linux implant was compiled into trojanized HAProxy load balancers, giving operators a way to intercept web traffic and serve altered pages on affected hosts. The backdoor also concealed its C2 activity from ordinary counters while supporting file transfer, shell execution, and configuration changes. The implant was found on two South Korean organizations in the automotive and media sectors, with only medium-confidence attribution to a North Korean cluster.
Related Happenings
MoYu Group campaign expands across multiple victims
Campaign
H score43
First: 21.08.2026 18:41
Last: 21.08.2026 18:41
Sources 1
About this happening:
Kaspersky says a supply-chain attack against Android-based car head units is using the legitimate DoFun update app TWCore to deliver JarService malware, wi...
MoYu Group campaign expands across multiple victims
CampaignAbout this happening: Kaspersky says a supply-chain attack against Android-based car head units is using the legitimate DoFun update app TWCore to deliver JarService malware, wi...
DoNot Team Bangladesh military and defence espionage campaign
Campaign
H score38
First: 17.07.2026 11:46
Last: 17.07.2026 11:46
Sources 1
About this happening:
A DoNot Team espionage campaign targeted Bangladesh's military and defence establishments, using spear-phishing RTF files to deliver a DLL implant and establish ...
DoNot Team Bangladesh military and defence espionage campaign
CampaignAbout this happening: A DoNot Team espionage campaign targeted Bangladesh's military and defence establishments, using spear-phishing RTF files to deliver a DLL implant and establish ...
Showboat Linux post-exploitation backdoor framework
Malware Activity
H score16
First: 21.05.2026 17:17
Last: 21.05.2026 17:17
Sources 1
About this happening:
The Showboat Linux malware has been identified as a modular post-exploitation framework used since at least mid-2022, raising the risk of persistent access on compromi...
Showboat Linux post-exploitation backdoor framework
Malware ActivityAbout this happening: The Showboat Linux malware has been identified as a modular post-exploitation framework used since at least mid-2022, raising the risk of persistent access on compromi...
QUIC RAT delivered through compromised DAEMON Tools installers
Malware Activity
H score37
First: 05.05.2026 19:07
Last: 05.05.2026 19:07
Sources 1
About this happening:
A follow-on QUIC RAT payload was delivered through compromised DAEMON Tools installers, extending the supply-chain intrusion into remote access on a small subset of in...
QUIC RAT delivered through compromised DAEMON Tools installers
Malware ActivityAbout this happening: A follow-on QUIC RAT payload was delivered through compromised DAEMON Tools installers, extending the supply-chain intrusion into remote access on a small subset of in...
Latest development: 07.05.2026 12:30
Disc Soft released malware-free Daemon Tools Lite Version 12.6 on May 5 after being notified of the supply chain attack on its build environment, and the affected 12.5.1 build was removed from distribution so users could move to the cleaned release.
AVB Disc Soft hit by network compromise
Incident
H score40
First: 05.05.2026 19:07
Last: 05.05.2026 19:07
Sources 1
About this happening:
DAEMON Tools suffered a supply-chain compromise when official installers were trojanized, enabling malicious payload delivery and raising the risk of downstream in...
AVB Disc Soft hit by network compromise
IncidentAbout this happening: DAEMON Tools suffered a supply-chain compromise when official installers were trojanized, enabling malicious payload delivery and raising the risk of downstream in...
Latest development: 07.05.2026 12:30
Disc Soft released the malware-free Version 12.6 of Daemon Tools Lite on May 5 after being notified of the supply chain attack, removed the affected 12.5.1 package from support, and said the incident was contained after isolating affected systems, removing compromised files from distribution, auditing the build and release pipeline, rebuilding and validating installation packages, and strengthening internal security controls and monitoring.
Timeline
-
04.09.2026 17:51 2 articles · 14h ago
Ted implant found inside trojanized HAProxy load balancers
Initial DisclosureRapid7 Labs found the previously undocumented Linux toolkit ted compiled directly into trojanized HAProxy load balancers at two South Korean organizations in the automotive and media sectors. The implant intercepted web traffic and served altered pages to selected visitors, and installing it required code execution on the host plus the ability to replace the running binary.
Show sources
- New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic — thehackernews.com — 04.09.2026 17:51
- New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic — thehackernews.com — 04.09.2026 17:51