malware
Published 2026-10-02
Verified 2026-10-07

Rapid7: new BPFDoor variant and a BPF Rekoobe build pose as SpamSniper on South Korean telecom and network systems, and a new SMTP-controlled Linux implant, AVERAT, hides in ShareTech appliances in Taiwan

Rapid7 published research on 2 October 2026 on Linux backdoors aimed at telecom and network-edge systems in South Korea and Taiwan that disguise themselves as the email security products in use locally. Against South Korean systems, a new BPFDoor variant impersonates the PID file of SpamSniper, a Korean anti-spam product, rotates through ten Linux daemon names, and in some builds names itself ora_ppmond to look like an Oracle database process; Rapid7 says operators now wrap the BPFDoor magic packet inside ordinary HTTPS POST requests so that SSL offloading at telecom edge proxies delivers the trigger past deep packet inspection, after which a TinyShell session gives shell, upload and download. A BPF backdoor built on Rekoobe watches traffic on port 25 and also uses SpamSniper component names. In Taiwan, a dropper planted in the add-on package directory of ShareTech appliances, keyed off the string "ShareTech", installs AVERAT, a previously unreported modular implant that uses SMTP on TCP port 25 for command and control, polling roughly every 10 to 11.5 minutes, with commands for file transfer, process control, up to 10 concurrent shells, proxying and loading extra modules; the payloads run from memory after their files are deleted. Rapid7 says the C2 infrastructure resembles an operational relay box network and treats attribution as ongoing; BPFDoor has previously been linked to the China-nexus group Red Menshen. Primary: Rapid7; wire: The Hacker News (7 Oct).

Product
Linux telecom and network-edge systems; SpamSniper (Jiran) and ShareTech email security appliances impersonated or abused
Versions
n/a — espionage malware; no product CVE disclosed
Exploited in Australia?
unknown
Patch to
On Linux servers and appliances that do not need packet capture, look for unexpected raw packet sockets and attached BPF filters, and for processes whose /proc/<pid>/exe link ends in (deleted). Alert on outbound TCP port 25 connections from anything that is not a mail service, look for processes posing as common daemons or Oracle background processes, and restrict management access to routers, mail gateways and other edge appliances. Rapid7's report lists file hashes, C2 domains and IP addresses.

Primary: Rapid7 — SMTP is the key: BPFDoor and AVERAT hitting the network edge (2 Oct 2026) · The Hacker News — Linux backdoors impersonate email security tools to evade detection in Korea and Taiwan (7 Oct 2026)

breaches network