Rapid7 Intelligence has disclosed a new modular Linux malware ecosystem that fuses fresh BPFDoor variants, a BPF-based Rekoobe build, and a novel AVERAT implant to compromise telecom and network-edge infrastructure in South Korea and Taiwan.[1][2][11] The campaigns concentrate on mail and security appliances at the perimeter, pushing command-and-control over SMTP and blending into legitimate mail flows to stay below the radar of conventional network monitoring.[1][2][4]
Researchers report that the operators rely on a Linux dropper that writes a shell script to targeted appliances, staging two binaries under innocuous daemon names such as ntpdate and udevds in /sbin before deleting the files while leaving the processes resident in memory.[1] One payload re-executes as a watchdog to maintain persistence without an on-disk footprint, while the other carries either an AVERAT implant or a BPFDoor variant customized to the vendor platform and role of the device.[1][4] In the South Korean cluster, the dropper derives its encryption key from the string ShareTech and resides in the appliance’s add-on package directory, while BPFDoor samples spoof local SpamSniper antispam software by impersonating its PID file and rotating through benign-looking Linux daemon identities.[1][4] A parallel cluster targets Taiwanese appliances with six AVERAT builds that adopt process names and configuration paths matching regional telecom and edge vendors, highlighting the operators’ detailed knowledge of their victims’ software stacks.[1][2]
Rapid7’s reconstruction of the BPFDoor controller source code shows the backdoor evolving from raw Layer 4 “magic bytes” in TCP and UDP headers to HTTP-tunneled triggers wrapped in ordinary-looking HTTPS POST requests traversing edge proxies in telecom environments.[1][3][15] Because proxies add and modify HTTP headers such as X-Forwarded-For and alter User-Agent lengths, the controller can no longer rely on fixed byte offsets; instead it sends mathematically padded requests like POST /admin/login.aspx?id=99990 so that the string 9999 consistently lands at a known position, then uses that marker to locate the rnrn separator and extract a hex-encoded command payload from the HTTP body.[1][3] The controller’s dogetlogin function hard-codes realistic web login paths to blend into logs, while the running process spoofs /usr/sbin/abrtd via Linux prctl calls, applying the disguise only on non-Solaris systems.[1][15] Newly documented flags add HTTPS POST tunneling, hidden IP fields, custom URI directories, and verbose debug output on top of older ICMP, UDP, and raw TCP trigger modes, giving operators flexible ways to activate implants and pivot within compromised networks.[1][3]
On the data plane, one newly observed BPFDoor variant creates a raw PF_PACKET socket and attaches a classic BPF filter that matches specific “magic” byte sequences in UDP, TCP, and ICMP traffic before opening shells or performing UDP knocks, depending on the password embedded in the trigger packet.[1] Strings inside the binary are obfuscated with a rotating substitution alphabet, but once decoded they reveal explicit product spoofing artifacts and a suite of process-name disguises that mimic common Linux daemons such as chronyd, rsyslogd, crond, and NetworkManager, alongside mutex references to /var/run/spamsniper.pid that tie the build to SpamSniper-protected mail and telecom environments in South Korea.[1][4] A separate sample gates on a unique 14-byte payload via a 16-instruction BPF program and spoofs its identity as ora_ppmond, echoing Oracle-backed HSS and OSS/BSS platforms used by telecom providers so that the implant looks legitimate only on hosts actually running that class of infrastructure.[1][2] Elsewhere, BPFDoor activity has been linked to the China-nexus group sometimes described as Red Menshen, but Rapid7 has not publicly pinned this latest SMTP-focused edge campaign to a specific threat actor.[7][8][15]
The AVERAT implants themselves are described as modular Linux remote access tools that favor SMTP over port 25 for command-and-control, allowing attackers to hide lateral movement and exfiltration inside the same mail security traffic defenders expect to see near the network core.[1][2][4] According to independent reporting, these operations also abuse compromised consumer and small-business appliances—including NAS devices, DVRs, and broadband gateways—as relays and persistence nodes, extending the reach of the ecosystem beyond traditional carrier gear into adjacent infrastructure.[2][11] That mix of fileless execution, vendor-specific process spoofing, passive BPF listeners, and mail-based C2 means conventional port-centric monitoring and simple process name checks are unlikely to surface the implants without more targeted hunting.[1][3][9] Rapid7 and other security firms have released BPFDoor detection scripts and guidance that focus on kernel-level BPF hooks, suspicious raw socket usage, anomalous process-command-line combinations, and unusual DNS, ICMP, or SMTP patterns, and telecom operators are being urged to apply those tools across edge proxies, mail gateways, and embedded devices as part of focused threat hunting and incident response.[3][9][12]
References
- SMTP is the key: BPFDoor and AVERAT hitting the network …
- opsecsafe — cyber intelligence
- BPFdoor in Telecom Networks: Sleeper Cells in the backbone
- Malicious Linux Implants Mimic Asian Mail Security Products
- Chinese Threat Actors Implant BPFdoor in Telecom Networks
- How to Detect and Neutralize BPFdoor Linux Malware in …
- Researchers release tool to detect stealthy BPFDoor …
- Rapid7 Launches Rapid7 Intelligence to Harness Threat …
- New stealthy BPFdoor malware variant discovered in …
- China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy …
