LINUX backdoors have been observed targeting telecom and network appliances in South Korea and Taiwan by disguising their traffic as email services and as legitimate processes. Researchers cited by Rapid7 found variants that impersonate components of email security tools, including SpamSniper and ShareTech, to blend in within enterprise environments.
Some BPFDoor samples spoof the SpamSniper PID file and cycle through multiple Linux daemon names to avoid casual detection, while other artefacts imitate an Oracle-backed TMON-style subsystem by naming a process ora_ppmond. In addition, a new BPFDoor variant and a Rekoobe-based build are used against South Korean targets, with a separate Linux implant named AVERAT delivered via a dropper to Taiwanese edge devices.
Technically, BPFDoor abuses Berkeley Packet Filter (BPF) to inspect traffic and trigger only on certain signals, such as a magic wake-on-LAN packet, wrapping the trigger in standard HTTPS POST requests to evade deep packet inspection at telecom edges. AVERAT uses SMTP (port 25) for C2 and to conceal activity, with an ELF dropper deploying the two binaries ntpdate (the dropper) and udevds (the AVERAT payload).
The implants implement a sizeable command set (including file and directory operations, process control, proxy channels, and remote shell access) and exfiltrate via a C2 under mx.zxopfds[.]com. Rapid7 notes the campaign aligns with regional threat activity and emphasises the importance of auditing Linux systems for unexpected raw sockets, BPF filters, and outbound port 25 connections, alongside monitoring for non-mail processes masquerading as daemons. While the research links to earlier Red Menshen activity, there is no confirmed connection to any known Operational Relay Boxes.