Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-05 ยท updated: 2026-09-05 ยท tags: [incident, backdoor, haproxy, supply-chain, traffic-interception] ยท confidence: high ยท affected_sectors: [technology, finance, government] ยท au_impact: true

New 'Ted' Backdoor Hides Inside Victims' Own HAProxy Builds

Security researchers disclosed a backdoor named "Ted" that hides inside legitimate HAProxy builds, persisting within the victims' own load-balancer software to intercept and manipulate web traffic. By embedding itself in the HAProxy binary rather than running as a separate process, the implant evades conventional process-based detection.

Attribute Detail
Implant "Ted"
Mechanism Hides inside legitimate HAProxy builds (supply-chain / source-layer)
Effect Intercept and manipulate web traffic; behaviour flows through existing infra
Detection Evades conventional process-based detection
Source The Hacker News โ€” Tier 2/4

Persisting inside an HAProxy binary lets the implant hide in plain sight while intercepting/live-modifying the web traffic that organisation's load balancers carry โ€” a significant supply-chain and network-security concern for AU/NZ orgs running HAProxy.

Source