RESEARCHERS from Rapid7 have detailed three new Linux backdoors that impersonate edge security appliances in Asia to blend in with normal network traffic. The campaigns, described as Korea- and Taiwan-based, see implants imitate legitimate anti-spam and mail-security software such as SpamSniper and a ShareTech information appliance, copying authentic processes, PID files, services and even BPF activation techniques to avoid detection.
The attackers extend the mimicry to data flow and traffic patterns, so the compromised devices appear as normal components of enterprise mail and edge protection ecosystems.
In the Korea-focused activity, known as the BPFdoor family with new Rekoobe variants, the implants use passive techniques and concealed activation codes within HTTPS requests. The related Rekoobe RAT also masquerades as SpamSniper and, in some variants, mirrors BPFdoor’s methods. The Taiwan operation centres on AVERAT, a modular RAT that communicates via TCP port 25 for C2, exploiting the perception that SMTP-related traffic is legitimate.
The AVERAT dropper installs two components, then deletes its malicious files, leaving otherwise normal processes running and making post-infection forensic work harder. The article emphasises that securing SEGs at the edge is challenging due to limited monitoring, closed vendor-managed environments and lack of baseline outbound mail traffic.
Detection guidance focuses on identifying anomalous deleted executables, unexpected raw packet sockets and specific dropper artefacts, with a reminder that restricting edge-management access and monitoring outbound port 25 remain practical controls. 2 October 2026