type: incident ยท created: 2026-09-05 ยท updated: 2026-09-05 ยท tags: [incident, backdoor, haproxy, supply-chain, traffic-interception] ยท confidence: high ยท affected_sectors: [technology, finance, government] ยท au_impact: true
New 'Ted' Backdoor Hides Inside Victims' Own HAProxy Builds
Security researchers disclosed a backdoor named "Ted" that hides inside legitimate HAProxy builds, persisting within the victims' own load-balancer software to intercept and manipulate web traffic. By embedding itself in the HAProxy binary rather than running as a separate process, the implant evades conventional process-based detection.
| Attribute | Detail |
|---|---|
| Implant | "Ted" |
| Mechanism | Hides inside legitimate HAProxy builds (supply-chain / source-layer) |
| Effect | Intercept and manipulate web traffic; behaviour flows through existing infra |
| Detection | Evades conventional process-based detection |
| Source | The Hacker News โ Tier 2/4 |
Persisting inside an HAProxy binary lets the implant hide in plain sight while intercepting/live-modifying the web traffic that organisation's load balancers carry โ a significant supply-chain and network-security concern for AU/NZ orgs running HAProxy.