Linux backdoors targeting telecom and network appliances in South Korea and Taiwan are disguising their traffic as email services and legitimate processes to evade detection. Rapid7 found new BPFDoor variants, a BPF Rekoobe build, and the previously unreported AVERAT implant, all using process spoofing, SMTP, and BPF-based stealth techniques. #BPFDoor #Rekoobe #AVERAT #SpamSniper #ShareTech #RedMenshen #UNC4841
Keypoints
- Threat actors are spoofing legitimate process and product names to hide malicious Linux backdoors.
- New BPFDoor variants were found targeting South Korean systems and impersonating SpamSniper.
- A BPF Rekoobe build and the AVERAT implant were used against telecom and appliance environments in Taiwan.
- AVERAT uses SMTP for command-and-control and stages payloads from the ShareTech appliance directory.
- Defenders should inspect raw packet sockets, BPF filters, suspicious TCP port 25 traffic, and fake daemon processes.
Read More: https://thehackernews.com/2026/10/linux-backdoors-impersonate-email.html