VYPR
researchPublished Oct 2, 2026· 1 source

Malicious Linux Implants Mimic Asian Mail Security Products to Evade Detection

New Linux backdoors, including variants of BPFdoor and Rekoobe, along with a novel implant named AVERAT, are sophisticatedly mimicking legitimate Asian mail security products to maintain stealth and exfiltrate data.

Cybersecurity researchers have uncovered a concerning trend where sophisticated malware developers are crafting Linux backdoors that meticulously imitate popular mail security appliances from South Korea and Taiwan. These implants go beyond superficial resemblance, mimicking filenames, network traffic patterns, and operational habits of legitimate software to achieve deep stealth within targeted networks.

Rapid7 researchers have documented two distinct but related campaigns employing these evasive backdoors. One cluster involves new iterations of the well-known "BPFdoor" implant and the "Rekoobe" remote access Trojan (RAT), while the other centers around a newly identified tool dubbed "AVERAT." These campaigns highlight a growing sophistication in malware designed to blend seamlessly into enterprise environments, particularly within the telecommunications sector.

The "BPFdoor" implant, notorious for its stealth, has evolved with new techniques to avoid detection. Recent variants have been observed masquerading as "SpamSniper," a South Korean anti-spam software, and as a background process associated with Oracle telecom platforms. This mimicry extends to its propagation methods, which include lying dormant until activated by specific codes within seemingly innocuous HTTPS requests and using ICMP pings to spread data within internal networks.

Adding to the complexity, the "Rekoobe" RAT has also been found impersonating "SpamSniper" within the same campaign. Both malware families are noted for their dedication to mimicry, copying legitimate software's Process ID (PID) files, system services, and common Linux services. Rekoobe even adopts BPFdoor's passive Berkeley Packet Filtering (BPF) activation technique, further blurring the lines between these distinct threats.

The choice of "SpamSniper" as a disguise is strategic, given its widespread use by over 6,000 organizations, including government ministries in South Korea. Similarly, the "AVERAT" implant and its associated dropper adopt the identity of a "ShareTech Information" appliance, a Taiwanese mail security vendor with tens of thousands of enterprise users across the Asia-Pacific region and beyond.

"AVERAT," a modular RAT, utilizes TCP Port 25, the standard port for Simple Mail Transfer Protocol (SMTP), for its command-and-control (C2) communications. This allows its traffic to blend in with normal email exchanges, making network-based detection significantly more challenging. The malware employs typical SMTP conventions before initiating encrypted sessions, further obscuring its malicious activity.

Compounding the evasion tactics, the attackers are using compromised edge devices like digital video recorders (DVRs) and network-attached storage (NAS) units as operational relay points. This diverts any attempts to trace the C2 servers, adding another layer of obfuscation. The strategy of compromising secure email gateways (SEGs) is particularly effective because these devices reside at the network edge, are often trusted by firewall rules, and are typically closed, vendor-managed systems that are difficult to monitor with standard endpoint security tools.

This sophisticated approach to malware deployment, leveraging deep knowledge of specific security products and network infrastructure, poses a significant challenge to defenders. The ability of these implants to maintain persistent access, exfiltrate data, and evade detection by mimicking legitimate network traffic underscores the evolving threat landscape and the need for advanced threat intelligence and monitoring capabilities.

Synthesized by Vypr AI