BPFDoor and AVERAT Malware Target Telecom Edge Devices Using SMTP for C2
Rapid7 reports on sophisticated BPFDoor and AVERAT malware campaigns targeting telecom network edge devices, employing novel techniques to evade detection and maintain command and control.

Security researchers at Rapid7 have detailed a coordinated malware campaign targeting network edge devices within the telecommunications sector, utilizing two distinct but related malware families: BPFDoor and AVERAT. The campaign is notable for its sophisticated evasion techniques, including the use of Simple Mail Transfer Protocol (SMTP) for command and control (C2) communications and the disguise of malicious processes as legitimate system daemons.
The attackers employ a multi-stage approach, beginning with a dropper that writes a shell script to the appliance's storage. This script then stages two payloads, masquerading them as legitimate system utilities like ntpdate and udevds, before executing them. Crucially, the dropper and its associated files are deleted from disk shortly after execution, while the malicious processes continue to run, making detection significantly more challenging. The dropper itself re-executes as a persistent watchdog, ensuring the malware's longevity.
New variants of BPFDoor, observed targeting South Korean systems, exhibit advanced evasion tactics. These variants wrap their trigger packets within standard HTTPS POST requests, leveraging the SSL offloading capabilities common in telecom environments. This method allows the malware to bypass traditional deep packet inspection (DPI) that might otherwise flag suspicious Layer 4 anomalies. To adapt to changes in HTTP headers introduced by proxies, the malware dynamically scans for payload data within HTTP requests, using mathematically padded requests to ensure consistent offset detection.
The AVERAT implant, with six observed builds deployed against Taiwanese appliances, shares some of the stealthy characteristics of BPFDoor. Both malware families are designed to blend seamlessly into their target environments. They achieve this by adopting names and conventions that mimic legitimate software and daemons running on the compromised devices. This regionalized disguise is a key tactic, with each sample demonstrating awareness of the specific vendor software present on the targeted systems, enabling effective process spoofing.
Beyond disguising their processes, the threat actors behind these campaigns are using SMTP for C2 communications. This choice is strategic, as SMTP traffic is often less scrutinized than other protocols, especially when disguised within legitimate-looking network traffic. While other implants might rely on DNS or TCP for outbound beacons, the use of SMTP provides an additional layer of stealth. The primary targets appear to be telecommunications operators and network edge infrastructure, including embedded devices like CCTV and DVR systems that are often situated close to the network core.
Rapid7's analysis also delves into the source code of a reconstructed BPFDoor controller, highlighting new features. These include the ability to specify a secondary "hidden" IP address for relaying magic packets and an option to activate HTTPS POST tunneling. The controller also allows for customization of the URI directory path to better blend with web server logs and includes a debug mode for enhanced visibility into crafted HTTP requests and responses. These enhancements demonstrate an ongoing effort by the attackers to refine their tools and maintain persistence.
The technical analysis reveals that the BPFDoor implants create raw PF_PACKET sockets with BPF filters to intercept network traffic. Upon matching specific magic byte sequences in UDP, TCP, or ICMP packets, the implant extracts the source of the command. The controller itself spoofs the identity of legitimate processes like /usr/sbin/abrtd using set_proc_name and PR_SET_NAME, further obscuring its malicious activity. This combination of network-level evasion, process spoofing, and stealthy C2 makes BPFDoor and AVERAT significant threats to critical network infrastructure.
Rapid7 provides indicators of compromise and hunting guidance for organizations to detect and defend against these sophisticated attacks. The findings underscore the evolving threat landscape targeting network edge devices and the critical need for robust security monitoring and incident response capabilities within the telecommunications sector.