B
今週中
韓国の自動車およびメディアセクターの組織において、HAProxyのバイナリに直接組み込まれた「ted」と呼ばれるバックドア
📌 一言でいうと
韓国の自動車およびメディアセクターの組織において、HAProxyのバイナリに直接組み込まれた「ted」と呼ばれるバックドアが発見されました。このツールはWebトラフィックを傍受し、特定の訪問者に改ざんされたページを表示させます。攻撃者はC2通信をHAProxyの接続カウンターから消去することで、ログや統計からの検知を回避しています。
🔍該当判定
- 自社で『HAProxy』というロードバランサー(負荷分散ソフト)を導入・運用している
- HAProxyをインストールしているLinuxサーバーに、外部から不正アクセスされた形跡がある
- HAProxyのバイナリファイル(実行ファイル)を、公式サイト以外から入手してインストールした
上記いずれにも該当しない → 静観でOK
✅該当時の対応
HAProxyバイナリの整合性チェック(ハッシュ値の検証)を実施し、不審な変更がないか確認してください。また、ホストへの不正アクセスを防ぐためのエンドポイントセキュリティの強化と、不審なアウトバウンド通信の監視を推奨します。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】HAProxy を標的としたバックドア「ted」について
お疲れさまです。HAProxy のバイナリを改ざんしてトラフィックを傍受する新種のバックドアに関する情報共有です。
■ 概要
北朝鮮系アクターによるものと推測される「ted」というツールが、HAProxy のバイナリに直接コンパイルされていました。C2通信を接続カウンターから消去するため、標準的な統計ログでは検知できない極めて隠蔽性の高い手法が用いられています。
■ 影響範囲
- 対象製品: HAProxy (攻撃者がホスト上のコード実行権限を持ち、バイナリを置換できた環境)
■ 対応手順
1. 稼働中の HAProxy バイナリのハッシュ値を、公式のクリーンなバイナリと比較し、整合性を検証してください。
2. サーバーへの不正アクセス(特権昇格)の形跡がないか、システムログを確認してください。
3. ネットワークレベルで、不審な外部通信(C2通信)が発生していないか監視を強化してください。
■ 参考情報
- Rapid7 Labs Report
対応優先度: 中
対応期限: 速やかに確認を推奨
お疲れさまです。HAProxy のバイナリを改ざんしてトラフィックを傍受する新種のバックドアに関する情報共有です。
■ 概要
北朝鮮系アクターによるものと推測される「ted」というツールが、HAProxy のバイナリに直接コンパイルされていました。C2通信を接続カウンターから消去するため、標準的な統計ログでは検知できない極めて隠蔽性の高い手法が用いられています。
■ 影響範囲
- 対象製品: HAProxy (攻撃者がホスト上のコード実行権限を持ち、バイナリを置換できた環境)
■ 対応手順
1. 稼働中の HAProxy バイナリのハッシュ値を、公式のクリーンなバイナリと比較し、整合性を検証してください。
2. サーバーへの不正アクセス(特権昇格)の形跡がないか、システムログを確認してください。
3. ネットワークレベルで、不審な外部通信(C2通信)が発生していないか監視を強化してください。
■ 参考情報
- Rapid7 Labs Report
対応優先度: 中
対応期限: 速やかに確認を推奨
Subject: [Security Alert] Backdoor 'ted' targeting HAProxy builds
Dear team,
We are sharing information regarding a newly discovered backdoor named 'ted' that hides within trojanized HAProxy load balancers.
■ Overview
Attributed with medium confidence to North Korean state-sponsored actors, this implant is compiled directly into the HAProxy binary. It intercepts web traffic and serves altered content. Notably, it erases C2 requests from HAProxy's connection counters, making it invisible to standard load balancer statistics and backend logs.
■ Scope
- Affected Product: HAProxy (specifically instances where attackers gained code execution and replaced the binary).
■ Recommended Actions
1. Verify the integrity of running HAProxy binaries by comparing hashes against known-good versions.
2. Audit system logs for unauthorized access or privilege escalation on the load balancer hosts.
3. Enhance network monitoring for anomalous outbound traffic that bypasses standard application logs.
■ Reference
- Rapid7 Labs Report
Priority: Medium
Deadline: Immediate review recommended
Dear team,
We are sharing information regarding a newly discovered backdoor named 'ted' that hides within trojanized HAProxy load balancers.
■ Overview
Attributed with medium confidence to North Korean state-sponsored actors, this implant is compiled directly into the HAProxy binary. It intercepts web traffic and serves altered content. Notably, it erases C2 requests from HAProxy's connection counters, making it invisible to standard load balancer statistics and backend logs.
■ Scope
- Affected Product: HAProxy (specifically instances where attackers gained code execution and replaced the binary).
■ Recommended Actions
1. Verify the integrity of running HAProxy binaries by comparing hashes against known-good versions.
2. Audit system logs for unauthorized access or privilege escalation on the load balancer hosts.
3. Enhance network monitoring for anomalous outbound traffic that bypasses standard application logs.
■ Reference
- Rapid7 Labs Report
Priority: Medium
Deadline: Immediate review recommended