Rapid7 finds Linux backdoors disguised as email traffic
Rapid7 detailed attacks on telecom and network-edge appliances in South Korea and Taiwan using a BPFDoor variant, a BPF Rekoobe build and an implant it calls AVERAT. AVERAT connects over TCP port 25 and speaks SMTP, blending into mail traffic, and checks in every 600 to 699 seconds.
- AVERAT uses TCP port 25 and SMTP with EHLO and STARTTLS
- The implant checks in every 600–699 seconds with up to 10 shell sessions
- BPF Rekoobe and BPFDoor impersonate SpamSniper processes
- Three AVERAT builds relay via a Synology NAS, Dahua DVR and legacy appliance
Read next
Security