BPFDoor and AVERAT Linux backdoors target telecoms in Korea and Taiwan
Rapid7 describes BPFDoor, Rekoobe, and six AVERAT builds hitting South Korean and Taiwanese telecom appliances while hiding operator traffic as SMTP and other protocols.
Rapid7's October 2, 2026 analysis covers Linux implants for telecom and network-edge devices: a new BPFDoor variant and a BPF Rekoobe build against South Korean targets, a dropper, and six AVERAT builds on Taiwanese appliances. The dropper stages ntpdate and udevds under /sbin, deletes those files while the processes keep running, and derives an encryption key from the string ShareTech; The Hacker News further says an ELF dropper on ShareTech appliances installs AVERAT and that the malware masquerades as the email-security products SpamSniper and ShareTech. BPFDoor impersonates SpamSniper, including PID files, and daemon names such as abrtd, uses BPF socket filters, and can take magic-byte triggers inside padded HTTPS POST requests before, per The Hacker News, opening a TinyShell session; Rapid7 says operator channels include DNS, TCP, and SMTP, and its notes also list raw UDP or ICMP, while the related Rekoobe backdoor watches port 25. AVERAT beacons on TCP port 25 with SMTP EHLO and STARTTLS—every 600–699 seconds according to Infosecurity Magazine, and to mx.zxopfds[.]com according to The Hacker News—with capabilities described as file transfer, process termination or control, up to ten concurrent shells, proxying, reboot, and loadable modules. Relays sit on compromised devices including a Synology NAS, an obsolete small-business appliance, and a Dahua recorder with attacker-installed PPTP VPN, consistent with CISA ORB profiles; telecom operators and nearby CCTV and DVR systems are the main exposure. Attribution is not consistent across sources: Infosecurity Magazine said it remains ongoing, whereas The Hacker News reports that Rapid7 links the BPFDoor activity to Red Menshen, also called Earth Bluecrow.
- Rapid7's analysis, published October 2, 2026, covers Linux implants aimed at telecom and network-edge devices in South Korea and Taiwan.
- The set includes a new BPFDoor variant and a BPF Rekoobe build on South Korean targets, plus a dropper and six AVERAT builds on Taiwanese appliances.
- The dropper runs fileless ntpdate and udevds from /sbin after deleting on-disk copies and derives an encryption key from the string ShareTech.
- BPFDoor spoofs SpamSniper, including PID files, and daemons such as abrtd, uses BPF filters, and can receive magic-byte triggers in padded HTTPS POST requests; The Hacker News says that opens a TinyShell session.
- AVERAT beacons on TCP port 25 via SMTP EHLO and STARTTLS (Infosecurity Magazine: every 600-699 seconds; The Hacker News: mx.zxopfds[.]com) and is described as supporting shells, file transfer, process control, proxying, reboot, and…
- Hardcoded relays include a Synology NAS, an obsolete small-business appliance, and a Dahua DVR with attacker-installed PPTP VPN, matching CISA ORB profiles; telecom gear and nearby CCTV/DVR systems are the main exposure.
- Attribution conflicts: Infosecurity Magazine said it remains ongoing, while The Hacker News says Rapid7 links BPFDoor to Red Menshen, also called Earth Bluecrow.
Coverage timelineoldest first · each row is one article
- · 6d agoSMTP is the key: BPFDoor and AVERAT hitting the network edge
Rapid7 Blog· 76
Rapid7 details BPFDoor and AVERAT Linux implants disguised as telecom-edge software in South Korea and Taiwan.
- · 3d agoNew Stealthy Linux Backdoors Target Telecoms, Masquerade as Email Traffic
Infosecurity Magazine· 68
Rapid7 documents stealthy Linux backdoors—BPFDoor, Rekoobe, and new AVERAT implant—targeting telecom and network-edge appliances in South Korea and Taiwan.
- · 2d ago