Linux backdoors targeting telecom and network-edge appliances in South Korea and Taiwan have been disguising their traffic as email and their processes as legitimate services on the devices they compromise.
In research published October 2, Rapid7 said it tracked a newly observed BPFDoor variant and a BPF Rekoobe build used against South Korean targets, along with a dropper and six builds of an implant it calls AVERAT deployed against Taiwanese appliances.
AVERAT connects out on Transmission Control Protocol (TCP) port 25 and speaks Simple Mail Transfer Protocol (SMTP), sending an email command (EHLO) and requesting STARTTLS before starting its own encrypted session. On a mail security gateway, where outbound mail is the device's core job, Rapid7 said the traffic is indistinguishable from legitimate work in flow records.
The implant checks in every 600 to 699 seconds, and its commands include file transfers, process termination, up to ten concurrent shell sessions and proxy or port-forwarding channels.
Mail Appliances Make Port 25 a Hiding Place
The BPF Rekoobe sample watches for traffic where both the source and destination ports are 25 and names its processes after components of SpamSniper, a South Korean anti-spam product. Rapid7 said firewall rules allowing mail relay between servers would let such a trigger packet reach the implant before any stateful inspection.
The South Korean BPFDoor variant also impersonates SpamSniper, while a separate BPFDoor sample named itself after processes on Oracle-based telecom subscriber platforms.
Rapid7 also detailed a BPFDoor controller that wraps its trigger in HTTPS POST requests, which it said may let the trigger pass through edge proxies and evade conventional deep-packet inspection.
Hijacked Devices Serve as Relays
Three AVERAT builds report to hardcoded addresses on compromised third-party devices in Taiwan: a Synology NAS, an obsolete small-business appliance and a Dahua video recorder.
All three ran an identical PPTP VPN service that Rapid7 believes the operators installed, opening a route into each victim's network.
Rapid7 said the relays match the device profile in an April 2026 advisory published by the US Cybersecurity and Infrastructure Security Agency (CISA) and partners on China-nexus covert networks, also known as operational relay box (ORB) networks. It found no overlap with any named ORB network and said attribution remains ongoing.
Rapid7 recommended investigating unexpected raw packet sockets and BPF filters, outbound port 25 connections from processes that are not mail services and processes posing as common daemons, and restricting management access to routers, DVRs and other edge appliances.
