securityonline.info 5 Oct 2026, 06:22 UTC

BPFDoor Campaign Hides Backdoors in Telecom Appliances and Mail Traffic

BPFDoor Campaign Hides Backdoors in Telecom Appliances and Mail Traffic

RAPID 7’s analysis describes a coordinated campaign deploying BPFDoor backdoors and the AVERAT implant on telecom and network-edge appliances. The attackers gain initial access previously, but Rapid7’s report does not detail the first intrusion. The dropper analysed by Rapid7 is a local installer for ShareTech appliances; its encryption key is derived from a hash of the vendor name “ShareTech,” suggesting the operators seed their own key material to fit target platforms.

Once run, the dropper copies two programs into a system folder under seemingly harmless names, launches them, and then deletes the copies ten seconds later. The processes persist in memory, leaving no on-disk payload for responders to find. One such program is the dropper itself, acting as a watchdog to rewrite the script if it is removed. The other is the AVERAT implant. The appliance’s startup processes likely relaunch the dropper at boot, creating a largely diskless, memory-resident intruder chain.

BPFDoor itself operates by a Berkeley Packet Filter that remains dormant until a “magic packet” appears, at which point it can open a remote shell or connect back to its controller without exposing a standard port. A South Korean variant masquerades as SpamSniper and cycles through common Linux service names; another sample imitates Oracle-based telecom subscriber platforms. A related Rekoobe backdoor listens on port 25 to exploit mail traffic as a covert trigger.

AVERAT uses SMTP to blend outbound commands with routine mail gateway traffic, reporting host details (hostname, user, OS version, network info) roughly every 10–11 minutes and enabling file access, uploads/downloads, multiple shells, proxying, and module loading. Relay infrastructure is hosted on hijacked devices in Taiwan (including a NAS, an outdated network appliance, and a CCTV recorder) running extra VPNs, complicating attribution.

The Rapid7/CSIA and UK advisories link the activity to China-nexus patterns, though no actor is named. Defense focuses on memory-forensics and unusual packet-filtering activity, not disk artefacts.

View full article

Article by CyberSIXT