Linux backdoors masquerade as email security products in Asia

Rapid7 has identified Linux backdoors targeting telecom and network appliances in South Korea and Taiwan that disguise their network activity and processes as legitimate email-security tools. The activity includes a new BPFDoor variant and a BPF Rekoobe build used against South Korean targets, alongside a previously unreported Linux implant called AVERAT deployed against Taiwanese appliances.
The samples do more than borrow generic Linux daemon names. They impersonate products familiar in their target environments, including SpamSniper, which Jiran Group markets as a leading Korean email-security solution, and ShareTech appliances in Taiwan. Rapid7 said the components adopt names and conventions intended to look unremarkable on the systems they compromise.
Regional product names conceal persistent access
BPFDoor variants found on South Korean systems impersonate SpamSniper's PID file and rotate through ten Linux daemon names. Another sample uses the process name ora_ppmond, echoing the ora_pmon_* naming convention associated with Oracle Database Process Monitor services used in telecom subscriber and provisioning environments.
BPFDoor abuses Berkeley Packet Filter functionality to inspect incoming traffic and activate only after detecting a magic packet. Once activated, the sample launches a TinyShell session and supports interactive shell access as well as file upload and download. Rapid7 described the malware as a modular framework that integrates TinyShell and Rekoobe logic to support exfiltration.
The newly observed version reflects continued adaptation after public detection work. Rapid7 said operators began targeting edge proxies after security vendors created Suricata and Snort signatures for Layer 4 anomalies. By placing the magic packet in ordinary HTTPS POST requests and relying on SSL offloading common in telecom environments, an operator may deliver the trigger to an infected node in a form that conventional deep packet inspection can miss.
SMTP traffic is used for AVERAT command and control
A separate Rekoobe-based BPF backdoor intercepts TCP, UDP and SCTP IPv4 traffic and UDP IPv6 traffic when both source and destination ports are 25. It also names its processes after SpamSniper components, extending the same disguise beyond a single implant.
In Taiwan, Rapid7 observed an ELF dropper in the ShareTech appliance add-on package directory, /addpkg/sbin/. It derives an encryption key from the string ShareTech, decrypts a shell script, and stages two binaries: ntpdate, the dropper, and udevds, the AVERAT payload. Both files are deleted 10 seconds later.
AVERAT polls its command-and-control server over TCP port 25 every 600 to 699 seconds, using encrypted configuration data for the server details and interval. Its commands can enumerate directories and processes, transfer files, delete data, open up to 10 shell sessions, reboot an appliance, load shared-object modules, change callback settings, and establish proxy or port-forward channels. Rapid7 said its infrastructure has the device-class profile associated with an Operational Relay Box network, without evidence tying it to a known ORB cluster.
Actions for Linux and edge-appliance operators
Rapid7 recommends reviewing unexpected raw packet sockets and BPF filters on Linux hosts that do not need packet capture. Teams should audit outbound TCP port 25 connections from processes that are not mail services, look for processes posing as common daemons, and restrict management access to routers, DVRs and other edge appliances.
For businesses operating telecom or network infrastructure, the practical implication is to treat familiar process names and email-related traffic as evidence requiring validation rather than as proof that a service is legitimate.

