Ted Backdoor Patches HAProxy to Intercept Traffic A newly described implant dubbed Ted is designed to hide inside a victim’s own HAProxy build, giving operators a stealthy position inside the web traffic path. The malware modifies the proxy binary rather than deploying as a separate process, allowing interception within routine application delivery workflows detailed in HAProxy builds already trusted in production.
https://thehackernews.com/2026/09/new-ted-backdoor-hides-inside-victims.html