Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan
Linux backdoors impersonating SpamSniper and ShareTech target telecom appliances in South Korea and Taiwan.
Rapid7 reported Linux backdoors targeting telecom and network appliances in South Korea and Taiwan that disguise themselves as email-security products SpamSniper and ShareTech. New BPFDoor samples, linked to Red Menshen, impersonate SpamSniper PID files, activate on a BPF magic packet, and can receive that trigger inside HTTPS POST requests before opening a TinyShell session. A related Rekoobe-based BPF backdoor watches traffic on port 25. An ELF dropper on ShareTech appliances installs AVERAT, which polls mx.zxopfds[.]com over TCP port 25 and supports interactive shells, file transfer, process control, reboot, and loadable modules.