# Rapid7 links HAProxy backdoor toolkit to North Korean actors

_Friday, September 4, 2026 at 10:51 AM EDT · Security · Latest · Tier 1 — Major_

![Rapid7 links HAProxy backdoor toolkit to North Korean actors — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgzLyhHupZwRy1pOQzT93Qhs5waZ8gqtlgDJUKgt1f37dz3KqIDDZY8uNo8QguZNccBHivdA_ecnY8cQUyhZQAvLH4APu3imxP-rwo2dYLZtKnJ92IkRPFmwepmJgRk9GrLrJiN_IbInwvNXaW7N5761YfEB1IIK4uDdNBTy6Koz8uXgOSXaQWixXM1Wts/s1700-nu-rw-lo-l85-e365/HAProxy.jpg)

Rapid7 Labs found a previously undocumented Linux toolkit compiled into trojanized HAProxy load balancers at two South Korean organizations. The implant, called ted in debug strings, intercepted traffic and could serve altered pages to selected visitors while concealing command-and-control requests from HAProxy counters. Rapid7 attributed the activity to North Korean state-sponsored actors with medium confidence and said more evidence is needed for a definitive assessment.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/new-ted-backdoor-hides-inside-victims.html)

---
Canonical: https://techandbusiness.org/newswire/abnwAPpismz55Gr2-658AK
Retrieved: 2026-09-05T00:44:14.473Z
Publisher: Tech & Business (techandbusiness.org)
