HAProxy Trojans Hide in South Korean Load Balancers
A Linux toolkit compiled into HAProxy binaries intercepts traffic for two South Korean firms, likely via state actors.
Researchers have uncovered a Linux backdoor compiled directly into the HAProxy load balancers of two South Korean organizations, where it silently intercepted web traffic and, in some cases, served altered pages to carefully selected visitors. The implant, which the attackers named ted in debug strings, represents a sophisticated method of persistent access that evades standard network monitoring.
A Stealthy Interception Mechanism
According to a report published Friday by Rapid7 Labs, the backdoor operates by intercepting requests that match specific criteria. When a request triggers the filter, the implant rewrites the content type and length on the way out, forces the response status to 200, and deletes the Accept-Ranges header. This prevents clients from noticing any size change through byte-range requests, making the altered responses appear completely normal.
The interception is designed to be invisible: Command-and-control (C2) requests never reach a backend server and are erased from HAProxy's own connection counters. This means neither the backend logs nor the load balancer's statistics record any trace of the malicious activity. The implant even decrements HAProxy's live connection counters to drop the connection from its statistics, leaving no audit trail.
Command Channel Disguised as Normal Traffic
To activate the C2 mode, the operator sends a request for a specific image path. Once triggered, the backdoor writes the command body to a named pipe under /tmp and zeroes the request channel, ensuring nothing is forwarded to the backend. Output returns on the raw socket under a standard HTTP/1.0 200 OK header, making the exchange look like ordinary web traffic.
Through this covert channel, the operator can issue a range of commands: beacon, upload and download files, run shell commands, and replace the implant's configuration. Only requests that pass four checks receive a modified page. The request must carry a User-Agent and match a rule where both URL and referer patterns fit. Delivery then depends on either whitelist membership of the client address (checked exactly and again at the /24 level) or an operator key in the Accept-Language header that overrides address filtering entirely.
Attribution to North Korean State Actors
Rapid7 Labs attributed the toolkit with medium confidence to North Korean state-sponsored actors, placing the two victims in South Korea's automotive and media sectors. The attribution draws on three separate North Korean clusters: APT37 for the domain list, Lazarus for the delivery model, and Kimsuky for the initial-access hypothesis.
Part of the attribution rests on a listing of the C2 domains under APT37 in maltrail, an open-source detection project. The maltrail file that Rapid7 links stopped resolving after a repository restructure in August moved the project's static trail data. The Hacker News confirmed on September 4 that all six domains are present at the new location, each labeled as APT37 infrastructure. The maltrail source file credits those entries to two posts on X from July 2025, without any reference to Rapid7.
“Further evidence is necessary to make a more definitive assessment,”
Rapid7 said in its report, acknowledging the limitations of the attribution.
Initial Access Hypothesis and Related Campaigns
Rapid7 said its evidence was not enough to establish a timeline or determine how the attackers first gained access. Its hypothesis that they came in through an exposed Groupware portal, a class of Korean enterprise collaboration software, rests on the ENKI research it points to. That report documented Kimsuky compromising a groupware vendor through a mail server flaw.
The researchers compared the delivery model to the Operation SyncHole campaign, in which visitors to South Korean online media sites were filtered by a server-side script and redirected. Kaspersky researchers Sojun Ryu and Vasily Berdnikov assessed “with medium confidence” that the redirected page may have run a malicious script against a flaw in Cross EX, a South Korean browser helper. Kaspersky's SyncHole report identified at least six victims in the software, IT, financial, semiconductor manufacturing and telecommunications sectors.
Toolkit Components and Evasion Tactics
The stager, which deploys only where HAProxy or cron is already running, verifies root before dropping anything. It overwrites the legitimate crond binary and gives the replacement the creation timestamp of /usr/bin/ssh. It then strips the keywords tmp, wget, cron and crond from root's bash history and from six system logs, among them auth.log and audit/audit.log.
Alongside the main backdoor, the toolkit includes a trojanized sshd that encrypts captured plaintext passwords and writes them to a fixed path. Rapid7 found the same code in trojanized agetty, atd, and polkitd binaries. A companion remote access trojan (RAT) that Rapid7 calls curlRAT beacons every 12 hours by default and drops to a 30-second interval when the operator sets a flag. It aborts unless it finds a marker file showing the host is virtualized.
curlRAT is distinct from CurlBack RAT, a separate family of that name attributed to the Pakistan-linked SideCopy group.
Indicators of Compromise
Rapid7 shared a list of domains and file paths associated with the campaign. The Hacker News confirmed on September 4 that none of the six domains resolves, returning NXDOMAIN for both A and NS records via Google Public DNS, meaning they are currently inactive. The domains are still useful for reviewing historical logs rather than for blocking live traffic.
The file paths and SHA-256 hashes provide additional clues for detection. Six further domains sit in the same two maltrail entries but not in Rapid7's list, and Rapid7 has not said whether they are the same infrastructure. The ThreatFox tag that Rapid7 names as its second source for the domains records five sightings, all timestamped July 2, 2025.
- Domains: img.monderhouse[.]space, img.smartnords[.]site, img.darklights[.]store, img.responsive.pstatic[.]autos, img.socialteams[.]store, img.worksongo[.]store
- Files: ~/cache/haproxy-1000.cache, /var/lib/sshd/c8c68e629bba773a10ac80012d10bf19, /var/lib/snapd/g580, /tmp/jasper-log
- SHA-256: 72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558, 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5
Impact on HAProxy Users
Both victims ran HAProxy 2.8.12, released on November 8, 2024. The implant reads HAProxy's internal structures at offsets fixed to that release, and Rapid7 does not specify whether other 2.8 builds exist. The current release on that branch is 2.8.28, from August 27, 2026, 16 point releases later. HAProxy's tracker lists 529 known bugs affecting 2.8.12 that are already fixed in the branch, including 1 critical and 16 major.
However, upgrading does not clean a host the implant already sits on, because the attackers replace the binary rather than exploit a flaw in it. Rapid7 recommended independent network correlation, memory behavioral analysis and binary integrity checks. The report publishes no detection rules for that last check, and a recompiled HAProxy reports the same version string as a clean build.
Why This Matters for Network Defenders
The discovery underscores that attackers are increasingly targeting the very infrastructure organizations trust to secure their traffic. By hiding inside HAProxy, the backdoor evades both backend and load balancer logs, making detection difficult even for organizations with strong network monitoring. The use of multiple North Korean threat clusters—APT37, Lazarus, and Kimsuky—suggests a coordinated effort to target South Korean organizations, with the media and automotive sectors being particularly exposed.
For defenders, this highlights the importance of verifying the integrity of critical binaries, not just applying updates. Since the backdoor replaces the HAProxy binary, standard upgrades won't remove it. Organizations should consider implementing binary integrity checks and behavioral analysis to catch such implants. The lack of detection rules from Rapid7 adds to the challenge, meaning defenders must rely on a combination of network correlation and memory analysis to identify similar compromises.
The development comes as AhnLab and ENKI WhiteHat documented a similar watering-hole campaign in July, in which state-sponsored operators abused compromised Korean websites to attack the AnySign4PC signing client. This pattern of targeting South Korean users through trusted software and infrastructure suggests an ongoing, evolving threat landscape that demands vigilance.
Sources
- The Hacker News Original source
- a report published Friday Also reporting
- the ENKI research it points to Also reporting
- a separate family of that name Also reporting
Continue Reading
Elementor Pro Flaw Exploited in the Wild
Attackers are actively exploiting a critical file upload bug in the popular Elementor Pro WordPress plugin.
G7 Makes Quantum Shift a Cybersecurity Priority
G7 calls for accelerated post-quantum cryptography transition, warning of near-term threats.
PaperCut Attacks Target Education Sector
Attackers exploit two PaperCut flaws to steal credentials from schools and universities in the U.S. and Europe.