Rapid7 said it tracked Linux backdoors made to look like software already on telecom systems. Its finds were a new BPFDoor variant, a Rekoobe-based build, a dropper and six builds of an implant it calls AVERAT. The Rekoobe build was seen against South Korean targets, and AVERAT against Taiwanese appliances. South Korean BPFDoor samples imitate the process-ID file of SpamSniper, an anti-spam product used mainly there.
BPFDoor listens through a packet filter and stays silent until a trigger packet arrives, so port scans miss it. Rapid7 said the dropper starts two programs from /sbin and deletes their files ten seconds later. They keep running, so there is nothing to hash or quarantine. AVERAT connects out on port 25, requests STARTTLS (encryption), then runs its own encrypted session. Rapid7 said this looks like routine work on a mail gateway. AVERAT's three relay addresses, recovered from its configs, are compromised Taiwanese devices: a Synology NAS, a Dahua recorder and a small-business appliance.
These disguises rely on what each device is trusted to do. A mail gateway sends mail, so port 25 draws no questions. Teams can ask who watches their edge devices, and whether anyone gets an alert when a process's executable shows as "(deleted)" in /proc.