Linux backdoors mimic email security tools in Korea and Taiwan
Rapid7 reports new Linux implants BPFDoor and AVERAT disguising traffic as SpamSniper and ShareTech to evade detection in Asian telecom networks.
Threat actors are deploying sophisticated Linux backdoors against telecom and network appliances in South Korea and Taiwan, disguising malicious traffic as legitimate email security services. Rapid7 identified these campaigns in October 2026, highlighting how attackers impersonate widely used enterprise products like SpamSniper and ShareTech to blend into local infrastructure.
What happened
The analysis reveals two distinct but overlapping operations targeting edge devices in the region. In South Korea, attackers deployed variants of BPFDoor and a BPF Rekoobe build. These implants specifically mimic the process identifiers and naming conventions of SpamSniper, a popular anti-spam solution from Jiran Group. The malware rotates through ten different Linux daemon names to appear unremarkable during casual inspection or automated scanning.
In Taiwan, a previously unreported Linux implant named AVERAT was discovered on ShareTech appliances. This malware is delivered via an ELF binary dropper located in the appliance’s add-on package directory. The dropper derives an encryption key from the string "ShareTech" to decrypt and execute its payload, which then establishes command-and-control communications over standard email protocols. Both campaigns demonstrate a high degree of regional awareness, tailoring the disguise to the specific software stack prevalent in each target environment.
How it works
BPFDoor leverages the Berkeley Packet Filter (BPF) functionality within the Linux kernel to inspect network traffic passively. Instead of listening on a open port that might trigger alerts, it waits for a specific "magic packet" to activate. To evade deep packet inspection systems that have learned to detect previous BPFDoor anomalies, operators now wrap these trigger packets in standard HTTPS POST requests. This technique exploits SSL offloading common in telecom proxies, allowing the trigger to reach the infected node without raising suspicion.
Once activated, BPFDoor launches a TinyShell session, enabling interactive shell access and file transfers. Another variant, Rekoobe, intercepts traffic on port 25, the standard port for Simple Mail Transfer Protocol (SMTP). Meanwhile, AVERAT uses SMTP directly for its command-and-control channel. It polls a remote server every 600 to 699 seconds, hiding its beaconing activity within normal email traffic flows. The AVERAT dropper cleans up after itself by deleting the staging binaries ten seconds after execution, leaving only the persistent implant running under a spoofed process name.
Key details
- BPFDoor variants impersonate SpamSniper PID files and rotate through ten Linux daemon names to avoid detection.
- AVERAT is a new modular implant targeting Taiwanese ShareTech appliances, using SMTP for command-and-control.
- The AVERAT dropper uses an encryption key derived from the string "ShareTech" to decrypt its payload.
- BPFDoor triggers are now wrapped in HTTPS POST requests to bypass deep packet inspection at edge proxies.
- AVERAT supports extensive commands, including file upload/download, process termination, and loading shared object modules.
- The activity is linked to Red Menshen, a threat group targeting telecom providers in Asia and the Middle East since 2021.
Why it matters
For engineers managing edge appliances and secure email gateways, this shift represents a significant escalation in evasion tactics. Traditional network signatures and port scans are ineffective against passive BPF implants that only wake up for specific triggers. By mimicking trusted local software like SpamSniper and ShareTech, these backdoors exploit the trust administrators place in known vendor binaries. This makes manual inspection difficult, as the process names and file paths appear legitimate at first glance.
Furthermore, the use of SMTP and HTTPS for command-and-control channels blends malicious traffic with essential business communications. Security teams often allow outbound traffic on port 25 and 443 without strict scrutiny, assuming it belongs to mail servers or web services. Attackers leverage this assumption to maintain persistence and exfiltrate data without triggering standard egress filters. This highlights the risk of relying solely on perimeter defenses for appliances that sit at the boundary of internal networks.
What you can do
- Audit Linux systems for unexpected raw packet sockets and BPF filters, especially on hosts that do not require packet capture.
- Monitor outbound TCP port 25 connections and alert on any process that is not a verified mail service attempting to use it.
- Scan running processes for names that mimic common daemons but exhibit unusual behavior or resource usage patterns.
- Restrict management access to routers, DVRs, and other edge appliances to authorized IP addresses and users only.
- Review the integrity of add-on packages on appliances like ShareTech to detect unauthorized binaries in directories such as "/addpkg/sbin/".
- Implement strict egress filtering to block unauthorized SMTP traffic from non-mail servers and inspect HTTPS traffic where possible.



