Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan

Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan
Linux backdoors targeting telecom and network appliances in South Korea and Taiwan are disguising their traffic as email services and legitimate processes to evade detection. Rapid7 found new BPFDoor variants, a BPF Rekoobe build, and the previously unreported AVERAT implant, all using process spoofing, SMTP, and BPF-based stealth techniques. #BPFDoor #Rekoobe #AVERAT #SpamSniper #ShareTech #RedMenshen #UNC4841

Keypoints

  • Threat actors are spoofing legitimate process and product names to hide malicious Linux backdoors.
  • New BPFDoor variants were found targeting South Korean systems and impersonating SpamSniper.
  • A BPF Rekoobe build and the AVERAT implant were used against telecom and appliance environments in Taiwan.
  • AVERAT uses SMTP for command-and-control and stages payloads from the ShareTech appliance directory.
  • Defenders should inspect raw packet sockets, BPF filters, suspicious TCP port 25 traffic, and fake daemon processes.

Read More: https://thehackernews.com/2026/10/linux-backdoors-impersonate-email.html