
North Korea-Linked Hackers Embed Backdoor in HAProxy Load Balancer Targeting South Korean Companies
APTBreakingNewsCyberWarfareMalwareSecurityBackdoorHackingHAProxyLinuxNorthKoreaSouthKoreaLoadBalancerSupplyChainAttack
North Korea-linked hackers embedded a backdoor inside the source code of HAProxy, a load balancing software, targeting two South Korean companies. The malware was hidden within the actual HAProxy code running at the network edge of these organizations. The backdoor enabled the attackers to mask command and control traffic and steal data while maintaining normal operation of the load balancer. The research was conducted by Rapid7.