New Stealthy Linux Backdoors Target Telecoms, Masquerade as Email Traffic
Rapid7 documents stealthy Linux backdoors—BPFDoor, Rekoobe, and new AVERAT implant—targeting telecom and network-edge appliances in South Korea and Taiwan.
Rapid7 research published October 2 details a newly observed BPFDoor variant and BPF Rekoobe build used against South Korean targets, plus a dropper and six AVERAT implant builds deployed on Taiwanese network-edge appliances. AVERAT beacons over TCP port 25 using SMTP EHLO and STARTTLS, making its traffic indistinguishable from legitimate mail on security gateways, and supports file transfers, process termination, up to ten concurrent shell sessions, and proxying. Implants report to hardcoded relays on compromised devices including a Synology NAS, an obsolete small-business appliance, and a Dahua video recorder running attacker-installed PPTP VPN, matching CISA ORB network device profiles. Attribution remains ongoing.