Skip to content
Brief Security & Trust ·

Rapid7: Linux backdoors copy local software names in Korea and Taiwan

Rapid7 says the malware imitates local software and hides its traffic in ordinary email connections.

In brief
  • Rapid7 tracked a new BPFDoor variant, a Rekoobe-based build and six AVERAT builds, each disguised as software common on its target.
  • Rapid7 says the running programs are deleted from disk, and the SMTP traffic looks routine on a mail gateway.

Rapid7 said it tracked Linux backdoors made to look like software already on telecom systems. Its finds were a new BPFDoor variant, a Rekoobe-based build, a dropper and six builds of an implant it calls AVERAT. The Rekoobe build was seen against South Korean targets, and AVERAT against Taiwanese appliances. South Korean BPFDoor samples imitate the process-ID file of SpamSniper, an anti-spam product used mainly there.

BPFDoor listens through a packet filter and stays silent until a trigger packet arrives, so port scans miss it. Rapid7 said the dropper starts two programs from /sbin and deletes their files ten seconds later. They keep running, so there is nothing to hash or quarantine. AVERAT connects out on port 25, requests STARTTLS (encryption), then runs its own encrypted session. Rapid7 said this looks like routine work on a mail gateway. AVERAT's three relay addresses, recovered from its configs, are compromised Taiwanese devices: a Synology NAS, a Dahua recorder and a small-business appliance.

These disguises rely on what each device is trusted to do. A mail gateway sends mail, so port 25 draws no questions. Teams can ask who watches their edge devices, and whether anyone gets an alert when a process's executable shows as "(deleted)" in /proc.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: Rapid7.