BlackTree Security · Infrastructure · Automation · AI

The Load Balancer Kept Working While a Hidden Backdoor Stole Credentials

A compromised load balancer does not have to stop working. The most useful backdoor may be the one that keeps every legitimate service running.

Rapid7 has uncovered a previously undocumented Linux espionage toolkit at two organisations in South Korea’s automotive and media sectors. Its most consequential component was not merely installed beside HAProxy. The attackers had recompiled HAProxy 2.8.12 with a malicious plugin inside it.

The modified load balancer continued handling real web traffic while the hidden code intercepted requests, stole session cookies, executed commands and selectively changed what visitors received. A wider collection of trojanised Linux services harvested passwords and maintained remote access.

Rapid7 attributes the activity with medium confidence to North Korea-aligned threat actors. The evidence supports that assessment, but it does not identify a specific group with certainty. The initial entry point is also unknown, and Rapid7 did not tie the compromise to a confirmed CVE.

The HAProxy backdoor lived inside a trusted process

Rapid7 calls the implant ted backdoor, based on debug strings left in the malicious code. The attackers compiled a custom filter named ted_plugin into the victim’s HAProxy build rather than relying on an obvious external web shell.

That design gave the implant access to HAProxy’s own HTTP parser, memory pools, event scheduler and process-management functions. It could inspect traffic after TLS termination, where request headers and session cookies were available in readable form. Normal load-balancing traffic continued towards the legitimate backend.

A specially formed request activated the command channel. The backdoor removed traces of that connection from several HAProxy counters and consumed the malicious request before it reached a backend server. A defender looking only at application logs could therefore miss both the command and the response.

The plugin also loaded targeting rules and encrypted configuration from hidden cache files. Those rules could select particular visitors by IP address, capture valuable traffic, inject scripts or redirect chosen users while leaving everyone else on the genuine site. That is a powerful surveillance position because the server can act normally for administrators, scanners and most customers.

The toolkit replaced the services defenders expect to trust

The HAProxy implant was only one layer. Rapid7 also found trojanised versions of sshd, crond, agetty, atd and polkitd. A modified SSH service captured plaintext passwords and stored them in an encrypted log. A stager profiled the host, checked for root privileges and replaced legitimate system daemons with malicious builds.

The delivery path was different from the malicious package examined in BlackTree’s RedC2 Linux backdoor analysis, but the defensive lesson is similar: a familiar service name is not proof that the code behind it is still trustworthy.

The stager also attempted to erase selected traces from shell history and Linux authentication, audit and system logs. File timestamps were copied from legitimate services to make the replacement binaries look older than the intrusion.

The accompanying curlRAT component could execute commands, download payloads, open reverse shells, provide an interactive terminal and report system information. Its default command interval was 12 hours, slow enough to reduce routine network noise, but an operator could switch it to a 30-second interval when active control was needed.

One thread watched HAProxy itself and reported whether the service had started, stopped, restarted or reloaded. The malware was not simply hiding from the load balancer. It was monitoring the health of the legitimate process that concealed it.

This was not an HAProxy supply-chain compromise

The distinction matters. Rapid7 found trojanised HAProxy binaries inside victim environments. It did not report that HAProxy’s official source code, release infrastructure or public packages had been compromised.

An administrator should therefore not interpret a matching HAProxy version as proof of infection. The malicious build used HAProxy 2.8.12, but version 2.8.12 itself is not the indicator. Binary provenance, package integrity, unexpected plugins, configuration artefacts and host behaviour are the evidence that matters.

The initial access path remains unresolved. Rapid7 observed exposed groupware and mail services and describes exploitation of a groupware portal as a plausible scenario consistent with previous North Korean operations. The available evidence was not sufficient to confirm that route or identify the vulnerability used.

Why Rapid7 links the activity to North Korea

The attribution is based on a combination of target selection, tooling characteristics and infrastructure. Both known victims were in South Korea, the custom encryption resembled techniques seen in related operations, and several command-and-control addresses had previously been associated with APT37 in public threat-intelligence sources.

Rapid7 rates the conclusion at medium confidence. BlackTree is therefore using “North Korea-linked” rather than presenting APT37 or another named group as proven. The espionage objective is also an assessment derived from the toolkit’s long-term surveillance functions and the targeted sectors.

This server-side operation complements, rather than replaces, the identity and recruitment tactics seen in other North Korean campaigns. BlackTree previously examined how North Korean IT workers reached sensitive environments through trusted identities. The HAProxy compromise shows the other side of the same strategic problem: legitimate infrastructure can continue looking useful after its trust boundary has failed.

What defenders should verify now

  • Verify HAProxy and affected system binaries against trusted vendor packages or independently built, reproducible baselines. Do not rely on version strings alone.
  • Inspect HAProxy configuration for unknown filters, hidden cache files and unexpected code paths. Rapid7 observed files named haproxy-1000.cache, haproxy-1001.cache and haproxy-1002.cache.
  • Review the integrity and provenance of sshd, crond, agetty, atd and polkitd, especially on internet-facing Linux systems.
  • Hunt for unexplained replacements, timestomping, changes to authentication logs and attempts to filter entries from shell history, audit logs or system logs.
  • Use Rapid7’s published hashes, domains, IP addresses and MITRE ATT&CK mapping to search endpoint, network, proxy and DNS telemetry.
  • If compromise is suspected, isolate the system and preserve evidence before rebuilding it from trusted media. Updating HAProxy alone does not remove a trojanised binary or the other replaced services.
  • Rotate SSH passwords, service credentials and administrative secrets handled by the affected host. Revoke web sessions and cookies that may have crossed the load balancer.
  • Determine whether selected visitors received injected scripts or redirects. The investigation may extend beyond the compromised server to users who browsed through it.

Organisations should also review why an attacker could replace core binaries without triggering an integrity alert. Package verification, measured boot, file-integrity monitoring and protected golden images are useful only when their results are monitored and cannot be quietly rewritten from the same compromised host.

The most dangerous outage is the one that never happens

Load balancers sit at a valuable trust boundary. They see decrypted requests, authentication cookies, internal destinations and the traffic patterns that reveal which users matter. Taking one offline would create an obvious incident. Keeping it healthy gives an espionage operator time.

The ted backdoor is consequential because it preserved the service it abused. Traffic flowed, websites loaded and administrators could still see a working HAProxy process. The infrastructure passed the availability test while failing the trust test completely.

Questions about the HAProxy backdoor

Was HAProxy itself compromised at the source?

No compromise of HAProxy’s official source, packages or release infrastructure has been reported. Rapid7 found attacker-modified builds inside two victim environments.

Is there a CVE to patch?

Not for the toolkit described by Rapid7. The initial access method and any vulnerability used remain unconfirmed. A normal software update should not be treated as complete remediation for a system whose core binaries may already have been replaced.

Has the North Korean attribution been proven?

Rapid7 attributes the campaign to DPRK-aligned actors with medium confidence. The target profile and infrastructure support that assessment, but a specific North Korean group has not been conclusively identified.

Sources and further reading

This article provides general security information. It is not incident-response, legal or attribution advice.

Leave a Reply

Your email address will not be published. Required fields are marked *