NEW stealth Linux backdoors have been disclosed targeting telecoms and network-edge appliances in South Korea and Taiwan, camouflaging their traffic as email and their processes as legitimate services. Rapid7’s October 2 briefing traces a BPFDoor variant and a BPF Rekoobe build used against South Korean devices, along with a dropper and six builds of an implant named AVERAT deployed against Taiwanese appliances.
AVERAT communicates over TCP port 25 and uses Simple Mail Transfer Protocol (SMTP), sending an EHLO command and requesting STARTTLS before establishing its own encrypted session. On mail gateways, where outbound mail is a core function, the traffic can be indistinguishable from legitimate activity in flow records. The implant polls the host every 600 to 699 seconds and can execute commands including file transfers, process termination, up to ten concurrent shell sessions and proxy or port-forwarding channels.
The researchers note that the BPF Rekoobe sample monitors traffic with both source and destination ports set to 25 and names its processes after components of SpamSniper, a South Korean anti-spam product, suggesting it can slip past firewall rules that allow mail relays. A BPFDoor variant also impersonates SpamSniper, while another sample masquerades as components on Oracle-based telecom subscriber platforms.
A BPFDoor controller is observed wrapping its trigger in HTTPS POST requests, potentially helping it traverse edge proxies and evade deep-packet inspection. Three AVERAT builds were found to hardcode addresses on compromised third-party devices in Taiwan—a Synology NAS, an obsolete small-business appliance and a Dahua video recorder—each running an identical PPTP VPN service.
Rapid7’s findings align with a CISA advisory on China-nexus covert networks and advise investigation of unusual raw packet sockets and BPF filters, unexpected outbound 25 connections from non-mail processes, and restricting management access to such edge devices. Attribution remains ongoing.