Trojanized HAProxy Turns a Load Balancer Into Spyware

Rapid7 says a previously undocumented Linux toolkit has been targeting South Korean automotive and media organizations since mid-2025 with a trojanized HAProxy 2.8.12 build, plus SSH keylogging and a curl-based remote access trojan. The campaign is tied with medium confidence to DPRK-linked operators. The malicious HAProxy plugs into the proxy’s normal traffic-handling hooks, so the service keeps balancing requests while it quietly logs high-value traffic, steals session cookies, and injects scripts for selected users. That means the compromise sits in the path of web sessions, not beside it, and a healthy-looking edge service can still be reading and altering what passes through. For organizations that use reverse proxies or load balancers as the front door to web apps, the exposure is the trust placed in that layer: if the proxy binary is owned, it can become a credential-collection point and surveillance node without taking the site down. Rapid7 could not pin down initial access, so the remaining question is how far this kind of edge compromise can spread in similar Linux estates.

Part of the PlainSec briefing for 2026-09-04

Every edition of this story: Trojanized HAProxy Turns a Load Balancer Into Spyware

Sources