Decision RecordActivePublished without chair review
CRT-2026-026709 Sep 2026AFTERNOON EDITIONDaily Roundtable
Response to trojanized HAProxy binaries
Revalidate HAProxy binaries, hunt for the documented process behavior, rebuild confirmed compromised hosts from known-good media, and investigate the preceding host intrusion rather than assuming HAProxy was the initial vulnerability or rebuilding the entire estate.
Current public guidance · the full record
What to do now
At a glanceThe edition's authoritative action board carries no action for this record's subjects — no What to do now guidance.
Why now
Partially supportedThe September 8, 2026 analysis provides exact integrity and behavior indicators for a malicious HAProxy build capable of file transfer and popen execution.
Because it reports that host-level code execution occurred before the legitimate HAProxy binary was replaced, defenders can act immediately on host containment and root-cause investigation without waiting for evidence of an HAProxy vulnerability.
Limiting rebuilding to confirmed compromised hosts avoids unnecessary estate-wide disruption while hunting continues.
Who is affected
Partially supportedHAProxy operators whose deployed binary matches SHA-256 72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558, ted_plugin, or build ID 24112201 face a binary capable of file transfer and popen execution.
Incident responders managing hosts with confirmed binary replacement or matching process behavior need host containment, root-cause investigation, and rebuilding from known-good media.
Operators of other HAProxy hosts need integrity and behavior checks, but the evidence does not justify rebuilding those hosts without compromise indicators. Two South Korean organizations were observed, but the packet does not establish that they define the campaign’s full scope.
No affected HAProxy version numbers are provided, so exposure cannot be determined by version alone.
What supports this
Partially supportedSupport — The September 8, 2026 Rapid7-based intelligence analysis reports host-level code execution before replacement of the legitimate HAProxy binary and reports no exploitation of an HAProxy vulnerability.
It identifies the analyzed build by SHA-256 72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558, ted_plugin strings, build ID 24112201, and a custom 14-byte command header; it also describes file transfer, popen execution, and FIFO behavior such as /tmp/t[ID]_w.pipe.
Support — The evidence auditor found that the cited analysis expressly supports integrity checking, behavior-based hunting, rebuilding confirmed compromised hosts, investigating the preceding intrusion, and avoiding an estate-wide rebuild.
Evidence gap — A separate source-quality review found that the direct Rapid7 analysis or equivalent authoritative corroboration is absent.
How the Roundtable reached this
Partially supportedThe intelligence analyst surfaced the reported sequence: host-level code execution preceded replacement of the legitimate HAProxy binary, and the analysis found no HAProxy vulnerability exploitation.
The decision scout translated that into integrity validation, behavior-based hunting, host-specific rebuilding, and investigation of the preceding intrusion. The evidence auditor supported those actions but identified the missing direct Rapid7 source.
The boundary reviewer resolved the scope question by limiting rebuilding to confirmed compromised hosts and excluding unsupported campaign attribution.
The linker found no comparable prior decision, and the arbiter selected a new operational decision based on host-focused containment and investigation.
Positions are generated by AI specialist personas and chaired by Halil Öztürkci.
Panel composition
- Scout (AI panel role)Scout identified 9 candidate signals.
- Linker (AI panel role)Linker evaluated 9 relation judgments.
- Evidence Auditor (AI panel role)Evidence Auditor recorded 20 evidence signals; 11 gaps.
- Prediction Steward (AI panel role)Prediction Steward accepted 1 prediction and rejected 1 claim.
- Boundary Reviewer (AI panel role)Boundary Reviewer recorded 13 public/private findings.
- Arbiter (AI panel role)Arbiter produced 9 decision envelopes.
Key disagreement
Scout (AI panel role)
North Korean sponsorship remains moderate confidence, and the two observed South Korean victims are a sample rather than a demonstrated campaign limit.
Arbiter outcome
Arbiter outcome: new decision record. The evidence directly supports host-focused containment, binary validation, and investigation of the preceding intrusion, with only peripheral source enrichment remaining.
Candidates considered
Considered 9 candidates · opened 1 · 8 not opened (8 other)
Considered, not opened
Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).
Sign in to preview practitioner entries.
What is uncertain
ConflictingThe initial host-intrusion method is unidentified.
No affected HAProxy version range is provided. The reported sequence and finding of no HAProxy vulnerability exploitation rely on a Rapid7-based account without the primary source in the packet.
DPRK state-sponsored attribution remains moderate confidence, and the two observed South Korean organizations are a sample rather than a demonstrated campaign boundary.
What evidence is missing
ConflictingThe packet does not include the direct Rapid7 analysis or another authoritative source corroborating the reported compromise sequence and absence of HAProxy vulnerability exploitation.
It also lacks affected HAProxy version numbers, vendor release evidence, trusted-release checksums, direct telemetry from the observed hosts, and evidence identifying the original entry method.
Primary evidence is also missing for the breadth of the campaign and the reported DPRK state-sponsored attribution.
What would change this
Partially supportedEvidence that an HAProxy vulnerability enabled initial access would add version-specific patching and broader exposure assessment to the response.
Discovery of the documented binary or behaviors on additional hosts would expand containment and rebuilding to those confirmed hosts. Authoritative evidence that refutes the reported compromise sequence would require reassessing the focus on a preceding host intrusion.
A verified trusted binary with no corroborating behavior would not support rebuilding that host solely because it runs HAProxy.
What to watch next
Partially supportedContinue binary-integrity and process-behavior hunting across HAProxy hosts.
Expand containment and rebuilding only when another host matches SHA-256 72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558, ted_plugin, build ID 24112201, the 14-byte command header, /tmp/t[ID]_w.pipe, or corroborating file-transfer and popen behavior.
Watch for a primary Rapid7 report or vendor advisory naming affected HAProxy versions, a CVE, or a fixed release; use it to revise patching and exposure scope. Also watch for evidence establishing the original intrusion route, campaign continuity, or stronger attribution.
Evidence basis
Tonight, authorize three actions in order: **1)** preserve Microsoft 365 sign-in evidence, then revoke only BigBear-linked bearer sessions and disable confirmed accounts—tenant-wide revocation would create avoidable disruption and MFA reset…
Rapid7 reports prior host-level code execution followed by replacement of the legitimate HAProxy binary; it found no HAProxy vulnerability exploitation. The analyzed build has SHA-256 `72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a…
Public value history
- 09 Sep 2026Initial public guidanceCurrent guidance
Created the first public value version for this Decision Record.
Source RoundtableAfternoon roundtableConvened 08 Sep 2026Methodology
How the panel reaches a Public Decision Record.