Rapid7 analyzed BPFDoor, BPF Rekoobe, and AVERAT samples that disguise themselves to match telecom and appliance environments, using port 25, BPF socket filters, and fileless staging to evade detection. The campaign affected South Korean, Taiwanese, and ShareTech/SpamSniper-related systems, including mail-security appliances, NAS devices, DVRs, and other edge infrastructure. #BPFDoor #BPFRekoobe #AVERAT #ShareTech #SpamSniper #ChunghwaTelecom
Keypoints
- Rapid7 tracked multiple Linux samples: a new BPFDoor variant, a BPF Rekoobe build, a dropper, and six AVERAT builds.
- The samples use regional and vendor-specific masquerading to blend into telecom and appliance environments, including SpamSniper and Oracle-like naming.
- The BPFDoor controller gained HTTPS POST tunneling through edge proxies, with padded requests to hide magic-packet delivery.
- The dropper writes a shell script to appliance storage, stages payloads in /sbin under fake names, and removes them after execution.
- AVERAT uses SMTP on port 25, STARTTLS, and custom encrypted handshakes to blend into legitimate mail traffic on relay appliances.
- Infrastructure included compromised Taiwanese devices and consumer/small-business edge equipment used as operational relays and VPN footholds.
- Defenders are advised to hunt for raw packet sockets, BPF filters, unlinked executables, hidden state files, and suspicious port-25 callbacks.
MITRE Techniques
- [T1584.008 ] Compromise Infrastructure: Network Devices â The operators used compromised NAS, DVR, and other edge devices as relays and footholds (âconsumer and small-business broadband CPEâ).
- [T1133 ] External Remote Services â AVERAT relays exposed PPTP on 1723 and were used as inbound access paths (âPPTP on 1723, present on all threeâ).
- [T1480 ] Execution Guardrails â The dropper executed only if /tmp/flag existed and the .php script was absent (âExecution is gated on one preconditionâ).
- [T1059.004 ] Unix Shell â The dropper and implant used shell commands and scripts to stage and launch payloads (â#!/bin/shâ, âsh -câ).
- [T1129 ] Shared Modules â AVERAT could load or unload shared-object modules to extend functionality (âLoad or unload a shared-object moduleâ).
- [T1037 ] Boot or Logon Initialization Scripts â The dropper relied on package/startup behavior to relaunch on boot (âpackage startup very likely relaunches it at bootâ).
- [T1205 ] Traffic Signaling â BPFDoor used magic packets and HTTP-tunneled triggers for covert activation (âmagic packetâ, âHTTPS POST tunneling modeâ).
- [T1205.002 ] Traffic Signaling: Socket Filters â BPFDoor and Rekoobe used classic BPF filters to detect magic traffic (âattaching a classic BPF filterâ).
- [T1070.004 ] File Deletion â The dropper removed staged binaries and scripts after execution (ârm -rf /sbin/ntpdateâ).
- [T1070.003 ] Clear Command History â AVERAT suppressed bash/vim logging to hide operator activity (ânot logged to bash history nor to vim logsâ).
- [T1070.006 ] Timestomp â BPFDoor-related behavior included misleading timing/cleanup patterns and deleted artifacts to obscure activity (âdelete each file ten seconds laterâ).
- [T1036.004 ] Masquerade Task or Service â BPFDoor spoofed service names and process identities (âspoofs the identity of /usr/sbin/abrtdâ).
- [T1036.005 ] Match Legitimate Name or Location â The samples used legitimate-looking names and paths such as ntpdate, udevds, and service paths (âblend into the software and device conventionsâ).
- [T1564.001 ] Hidden Files and Directories â AVERAT used hidden state files such as /var/lib/.db and other dotfiles (âpersistent across restartsâ).
- [T1027 ] Obfuscated Files or Information â BPFDoor and AVERAT hid strings and configuration with encoding, XOR, and encrypted blobs (âStrings are hiddenâ, âencrypted blobâ).
- [T1027.013 ] Encrypted/Encoded File â The dropper and AVERAT stored payload/configuration in AES- and RC4-protected blobs (âAES-128-ECB blobsâ, â276-byte encrypted blobâ).
- [T1140 ] Deobfuscate/Decode Files or Information â The article describes decoding hidden strings and decrypting configuration to reveal paths, keys, and commands (âDecoding revealsâ).
- [T1562.004 ] Disable or Modify System Firewall â BPFDoor used NAT redirection and firewall-aware techniques to bypass inspection (âiptables NAT-redirect staging/teardown logicâ).
- [T1083 ] File and Directory Discovery â AVERAT enumerated directory contents and walked file trees (âEnumerate directory contentsâ).
- [T1057 ] Process Discovery â AVERAT enumerated running processes with command lines (âEnumerate running processes with command linesâ).
- [T1082 ] System Information Discovery â AVERAT collected hostname, OS version, and other system details (âreport hostname, current user, OS versionâ).
- [T1033 ] System Owner/User Discovery â AVERAT reported the current user and logged-in users (âcurrent userâ, âlogged-in usersâ).
- [T1016 ] System Network Configuration Discovery â AVERAT collected network interfaces as part of beaconing (ânetwork interfacesâ).
- [T1005 ] Data from Local System â The dropper staged local files and paths from the appliance filesystem (âthree paths and a scriptâ).
- [T1041 ] Exfiltration Over C2 Channel â AVERAT sent collected host data back through its command channel (âEach reports hostnameâŚâ).
- [T1030 ] Data Transfer Size Limits â AVERAT used chunked uploads and resumable downloads (âUpload a fileâŚin chunksâ, âDownloadâŚwith resume supportâ).
- [T1105 ] Ingress Tool Transfer â The dropper installed payloads by copying them from /addpkg into /sbin (âcopies AVERAT into /sbin/udevdsâ).
- [T1071.003 ] Application Layer Protocol: Mail Protocols â AVERAT communicated over SMTP and STARTTLS on port 25 (âIt connects outbound to port 25 and speaks SMTPâ).
- [T1573.001 ] Encrypted Channel: Symmetric Cryptography â AVERAT and Rekoobe used TLS and application-layer encryption (âHMAC-SHA1, AES-CBCâ, âSTARTTLSâ).
- [T1090 ] Proxy â AVERAT included proxy and port-forward capabilities (âOpen a proxy or port-forward channelâ).
- [T1008 ] Fallback Channels â BPFDoor and related samples used alternative trigger modes and networking paths (âICMP modeâ, âUDP modeâ, âHTTPS POST tunneling modeâ).
- [T1529 ] System Shutdown/Reboot â AVERAT could reboot the appliance after syncing buffers (âsync() before forcing a restartâ).
- [T1489 ] Service Stop â The reboot and teardown behavior could stop services and flush state (âforcing a restart through the kernelâ).
Indicators of Compromise
- [SHA-256 ] Dropper and AVERAT samples â 2bedc26d4b29b435c21962beed7db21188a0219a0d28334bba8b4fb1656d7b15, bf8135f46ecedfe5bd06fcecbb2e721c2367ff765b18f4aa3f868e6597f49e47
- [SHA-256 ] Additional AVERAT and BPFDoor family samples â 4925bcca085ec504f51191645da278d8e96698d91f3c6df44146336c697b4de8, a4379e115d3c4420f5d4b92561022d6e0897990e7297be65c033d47de68e6a6a and 4 more hashes
- [SHA-256 ] SpamSniper BPFDoor and Rekoobe builds â a37ea9897221d4495b538de72b74f2aa1d2ff09b7b6dcedd395aee58931adbf3, 7e667ba5f9df912e02275d3cfe3809d16f822fe776f4035c84b118ebd925b1b5
- [Domain ] AVERAT C2 infrastructure â mx.zxopfds.com, spam.suwaccqi.com and mx1.wwstifsteel.com
- [IPv4 ] AVERAT C2 or relay hosts â 59.125.211.65, 122.116.138.33 and 1.34.200.85
- [File/Path ] Dropper and staging artifacts â /HDD/ms6x2xTo64/updIptable.php, /HDD/ms6x2xTo64/execProcEnd and /tmp/flag
- [File/Path ] Hidden AVERAT state files â /var/lib/.db, /var/lib/.sencha and /var/lib/.us
- [File/Path ] BPFDoor mutex and staged binaries â /var/run/spamsniper.pid, /sbin/ntpdate and /sbin/udevds
- [File/Path ] Dropper payload sources â /addpkg/sbin/update and /addpkg/sbin/agetty
- [Port ] Network communication and C2 â TCP/25, 1723 and other mail-related callbacks
- [Crypto/Protocol Constants ] AVERAT protocol and beacon material â 1571 / 0x0623, 5d 0c f9 47 e4 ea 7b 18 1b ed 5e b1 fb 5c 56 3f and 6b 6a 48 0e f8 ae 5f 1b 38 e6 c0 94 86 df e3 45
Read more: https://www.rapid7.com/blog/post/tr-smtp-is-the-key-bpfdoor-averat-hitting-the-network-edge