How to prove your HAProxy build is legitimate
On September 4, Rapid7 Labs published research on a Linux espionage toolkit found at two organizations in South Korea. The centerpiece is a backdoor the researchers call "Ted," which was hidden inside a modified HAProxy build running on the victims' load balancers. Rapid7 attributes the campaign to North Korean state-sponsored actors with medium confidence. The same toolkit tampered with multiple tools across the victims' systems, including an SSH keylogger.