New variants of the Linux backdoors BPFDoor, Rekoobe and a fresh implant called AVERAT have been identified in network and telecom devices in South Korea and Taiwan. They disguise themselves as legitimate email security tools SpamSniper and ShareTech solutions, use the Berkeley Packet Filter and SMTP-based command-and-control, and thus almost blend into normal traffic. Telecom operators and organizations that rely on email gateways are at greatest risk, and the top priority for administrators is to check for hidden BPF filters, raw sockets and outgoing TCP connections on port 25 originating from processes unrelated to the mail infrastructure.
Technical details: how the new backdoors work
Modernized BPFDoor and BPF-based Rekoobe
The BPFDoor family is already known for abusing Berkeley Packet Filter capabilities: the malicious process “listens” to traffic at a low level and activates only upon receiving a special “magic packet”, similar to the Wake-on-LAN mechanism. This makes the backdoor hard to detect both for classic port scans and for simple tools monitoring network connections.
In the new campaigns against Korean targets, BPFDoor goes beyond simply disguising the file name. Some samples:
- substitute the PID file and process names, imitating components of the anti-spam solution SpamSniper, which the developer Jiran Group positions as “the leading email security solution in Korea” (SpamSniper product description);
- cycle through ten names that resemble common Linux system daemons to complicate manual analysis of the process list;
- in one case name the process ora_ppmond, clearly alluding to the Oracle Database background Process Monitor (PMON) whose naming follows the pattern
ora_pmon_*, as described in Oracle documentation (Oracle NCC guide).
After receiving the trigger packet, BPFDoor establishes a TinyShell session — a minimalist remote administration shell that allows the attacker to execute commands and upload and download files. TinyShell is described in detail, for example, in the Wikipedia article and has previously been associated with several clusters linked to China. This choice of tool gives the attacker a flexible interactive shell on top of an initially passive BPF backdoor.
Researchers have also observed a BPF-based variant of Rekoobe that intercepts IPv4 TCP/UDP/SCTP traffic and IPv6 UDP packets where both the source and destination use port 25 (SMTP). This component also disguises its processes as SpamSniper parts. Essentially, it is a targeted SMTP traffic interceptor embedded in the network stack, which makes detection based on ports and connections non-trivial. Classic Rekoobe was previously analyzed in detail, for example, in a publication by Intezer (Linux Rekoobe analysis).
A further complication is adaptation to telecom network architecture. Once static Suricata/Snort signatures for layer‑4 anomalies specific to BPFDoor were created, operators began “wrapping” the magic packet into standard HTTPS POST requests. Because SSL decryption is commonly offloaded to separate proxies in telecom environments, the compromised internal system receives the already decrypted trigger, but external TLS-traffic analysis systems do not see it.
AVERAT: SMTP implant inside ShareTech appliances
In the Taiwanese part of the infrastructure, attackers are using a previously undescribed implant named AVERAT, running on ShareTech devices (ShareTech official website). Delivery is carried out via an ELF dropper placed in the /addpkg/sbin/ directory on the device, which acts as a local installer.
Key characteristics of the dropper and AVERAT:
- the dropper calculates an encryption key based on the string
"ShareTech"and uses it to decrypt an embedded shell script; - the script deploys and launches two binaries:
ntpdate(the dropper itself, posing as the standard time client) andudevds(the main AVERAT process); - both files are deleted roughly 10 seconds after launch, reducing artifacts on the file system and shifting the emphasis to running processes and network activity;
- AVERAT connects every 600–699 seconds to the command-and-control server mx.zxopfds[.]com over TCP port 25, using SMTP as the C2 transport so as to look like regular email traffic.
The backdoor’s functionality is defined by a system of numeric commands, including:
- 20 — list directory contents;
- 21/22 — download and upload files with support for resuming transfers and sending in chunks;
- 25 and 30 — recursive deletion and traversal of directory trees;
- 629/632 — inventory and termination of processes on the host;
- 842 — dynamic change of C2 addresses and ports without reinstallation;
- 912/914 — opening up to 10 simultaneous interactive shell sessions and sending commands into them;
- 916 — rebooting the device;
- 1010 — loading and unloading
.somodules, turning AVERAT into a modular platform; - 1576 — modifying the callback interval with storage in a local database;
- 1618 — setting up proxying or port forwarding through the compromised appliance.
This set of capabilities gives attackers full control over the device: from covert file operations and interactive administration sessions to using the appliance as a proxy node for further movement inside the network.
Researchers note that AVERAT’s C2 infrastructure resembles Operational Relay Box (ORB)-class networks, as described, for example, by Team Cymru (introduction to ORB networks). However, no linkage has yet been found to known orbits such as LapDogs, SPACEHOP or FLORAHOX.
Threat context: focus on telecom and email gateways
BPFDoor has already been analyzed in detail by Rapid7 specialists; the activity is attributed to the group Red Menshen (also known as Earth Bluecrow, DecisiveArchitect and Red Dev 18), which, according to public data, has been deliberately targeting telecom providers in the Middle East and Asia since 2021. The new samples confirm the trend: emphasis on network perimeters and high‑privilege devices.
The use of TinyShell in recent BPFDoor variants is consistent with previously observed operations by other China‑associated clusters (Liminal Panda, UNC3886, Velvet Ant) targeting telecom networks and edge devices, as described, for example, by Sygnia in its analysis of the Velvet Ant campaign (Operation Highland: Velvet Ant).
The choice of entry point deserves special attention: email gateways and mail infrastructure. In 2023 another group, designated as UNC4841, actively exploited CVE-2023-2868 and CVE-2023-7102 in the Barracuda Email Security Gateway to install persistent backdoors; entries in NVD have been published for these CVEs (CVE-2023-2868, CVE-2023-7102). The current research shows a similar strategic calculus: control over the device that corporate email passes through and is filtered on gives the attacker a valuable vantage point for reconnaissance and a command channel disguised as “background” SMTP.
Impact assessment and risk profile
The following categories of organizations are most vulnerable:
- telecom operators and communication providers in South Korea and Taiwan;
- large and mid-sized companies in the region using SpamSniper and ShareTech solutions as email gateways or network firewalls;
- organizations with extensive fleets of network appliances (routers, DVRs, specialized gateways) where management is pushed to the periphery and is poorly covered by workstation and server monitoring tools.
Potential consequences of an undetected compromise include:
- stealthy long-term access to network infrastructure with the ability to quietly monitor traffic and gradually advance the attack;
- compromise of correspondence, leakage of confidential information and credentials from email flows;
- use of devices as intermediate nodes (proxies and tunnels) for attacks on other organizations, increasing legal and reputational risks for the infrastructure owner;
- risk of operational disruptions (for example, rebooting a critical appliance on a backdoor command) and violation of contractual service availability obligations.
The difficulty lies in the fact that BPFDoor, Rekoobe and AVERAT are all designed not to generate “noise” at the level of familiar indicators: ports, process names and even communication protocols appear normal for the target environment.
Practical security recommendations
1. Audit of network appliances and email gateways
- Compile an inventory of all email gateways and edge devices (including telecom equipment, DVRs, specialized Linux appliances) and single out instances with SpamSniper and ShareTech products.
- Check directories analogous to
/addpkg/sbin/on ShareTech devices for suspicious ELF binaries and transient files appearing under the namesntpdateandudevds. - Compare the list of running processes with the expected set for the specific hardware solution according to vendor documentation (Jiran Group for SpamSniper, ShareTech for its systems).
2. Detection of anomalous use of port 25
- Restrict outgoing TCP connections to port 25: allow them only for official mail servers and gateways, and block them for other devices.
- Configure logging of all outgoing connections to port 25 from non-mail processes; treat persistent connections at intervals of roughly 10–15 minutes as suspicious.
- On Linux systems, periodically check which processes are bound to port 25, for example using
ssornetstat, and manually review suspicious names.
3. Searching for processes masquerading as system services
- Check for processes with names similar to SpamSniper and ora_ppmond, especially on servers where Oracle Database is definitely not used.
- Scan the list of daemons for names that look “too generic” and are not backed by real binaries in standard directories (
/usr/sbin,/sbin, etc.). - Correlate PID files in
/var/run(or/run) with actually existing processes and executables; anomalous SpamSniper-branded PID files on non-mail servers are grounds for immediate investigation.
4. Controlling BPF filters and raw sockets
- On Linux systems where there is no legitimate need for traffic interception (e.g., debugging, IDS, diagnostics), check for raw sockets and active BPF programs/filters.
- Introduce an approval process for any new packet-capture tools (tcpdump, custom monitoring agents) to eliminate undocumented components.
- Use system auditing (auditd or equivalents) to log operations related to creating raw sockets and loading BPF programs, especially on edge devices.
5. Securing management and segmentation
- Move management of telecom equipment, email gateways, routers and DVRs to a separate management network segment accessible only via VPN and strictly limited access control lists.
- Prohibit direct access to the management interfaces of these devices from user subnets and from systems not related to administration.
- Regularly check whether such devices are being used as transit nodes (proxies, tunnels) for traffic that does not match their intended purpose.
The key takeaway from the identified campaigns is that network and email appliances in Korea and Taiwan are already being used for covert access via BPFDoor, BPF Rekoobe and AVERAT. Therefore, in the near term, priority should be given to targeted assessment of precisely these devices — focusing on hidden BPF filters, masquerading processes and outgoing SMTP traffic from non-mail services.