Back Darkreading Malicious Linux Implants Mimic Asian Mail Security Products
Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa, the Asia Pacific, Europe, and Latin America.
A trio of newly discovered backdoors walk and quack like legitimate edge solutions, so it's hard to tell they're not.
Cutting-edge malware developers have been using their intimate knowledge of Korean and Taiwanese network edge appliances to build Linux implants that infect and mimic them to an extraordinary degree.
It's common enough for malicious software to imitate legitimate software, superficially. An unwelcome program might name itself after something it expects in its target environment, so that if a passerby spots it, they might not think much of it. A few new Linux backdoors go further than this, though, by imitating the filenames, firewall-allowed traffic, and other specific operating habits of the popular Asian email security appliances they infect.
Researchers at Rapid7 have documented two adjacent, in some ways overlapping campaigns involving these backdoors. One cluster includes new variants on the infamous " BPFdoor " implant, and a new BPFdoor-esque iteration of the old "Rekoobe" remote access Trojan (RAT). The other is built around a novel tool called "AVERAT."
Related: UAE, Saudi Arabia Face Onslaught of Increasingly Complex Cyberattacks
The Korea Campaign: BPFdoor, Rekoobe
For years now, "BPFdoor" has been one of the stealthier backdoors known to the cybersecurity industry. In May, Rapid7 documented two of its newest, ultra-quiet listening and propagating techniques . In short: The malware lay dormant, waiting for an activation code located at a specific byte within incoming, seemingly harmless HTTPS requests. And it could propagate data to specific, identified computers deeper within target organizations by inserting a code into innocuous Internet Control Message Protocol (ICMP) pings.
Researchers also found that another longstanding Linux RAT, "Rekoobe," has been masquerading as SpamSniper, as part of the same general campaign. The two malware tools take their mimicry seriously, copying the legitimate software's Process ID (PID) file, system services, and commonly used Linux services. Rekoobe also mimics BPFdoor, in a way, by copying its passive Berkeley Packet Filtering (BPF) activation technique.
That these programs chose SpamSniper as a muse is no accident, and this likely indicates which sorts of targets they're being aimed at: According to Japanese B2B platform IPROS , SpamSniper was used by more than 6,000 organizations as of July 2023. Jiran Group, the vendor, boasts on its website supplying customers across the Asia-Pacific region, including central government ministries and public institutions in South Korea.
Related: Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites
The Taiwan Campaign: AVERAT
Confusingly, the new Rekoobe RAT shares cryptography routines with a malware dropper belonging to seemingly a separate campaign. The dropper adopts the identity of a ShareTech Information appliance. ShareTech is a Taiwanese mail security vendor that, according to its website , services large enterprises, educational institutions, and government entities. It claims to enjoy "tens of thousands of enterprise users in Taiwan ," and, according to its page, organizations in India, Indonesia, Japan, Kenya, and Thailand.
The ShareTech dropper installs two programs: itself — again, in a loop, in case anything goes wrong — and AVERAT. Then it waits 10 seconds and deletes all of the malicious files it dropped, leaving only the running processes in place to limit leftover evidence.
AVERAT is a mostly straightforward modular RAT. Its most effective quality, which it shares with the new Rekoobe, is using Transmission Control Protocol (TCP) Port 25 for command-and-control (C2). Port 25, the traditional network port for the Simple Mail Transfer Protocol (SMTP), allows AVERAT and Rekoobe to communicate with their puppet masters in a way that blends with normal email traffic. AVERAT also makes sure to use typical SMTP conventions before beginning an encrypted session. In the end: All it looks like is email activity going to some arbitrary mail exchanger (MX) — an utterly normal occurrence in any enterprise environment.
Related: 'Breeze Comet' Tears Into Brazilian & Global Financial Systems
As an added bonus: In case anyone goes looking for the servers these programs are communicating to, they'll instead run into popped edge devices — digital video recorders (DVRs), network-attached storage (NAS) units, etc. — used as operational relay points .
Why Exploiting SEGs Works
Infecting and blending into secure email gateways (SEGs) turns out to be a pretty good strategy for intelligence gathering, says Christiaan Beek, vice president of Rapid7 Intelligence.
First off, SEGs occupy a privileged position in targeted networks. "These devices sit at the network edge, on the path between the Internet and the core, and are often trusted by the firewall rules around them. A foothold there is well placed for long-term access, particularly in telecom environments," Beek explains.
Even more problematic, "These appliances are closed, vendor-managed boxes that typically can't run endpoint detection and response (EDR) or other endpoint agents. Few organizations monitor them closely, so an implant can sit there for a long time," he says.
Adding to the pile, "File-based detection doesn't work here because nothing persists in the directory. Network detection takes more effort too, because you have to fingerprint the implant's fixed Transport Layer Security (TLS) handshake rather than just watching a port, and the port can be changed at runtime," he says. "Many organizations also lack a baseline of what normal outbound mail traffic from their appliances looks like, which is what makes the anomaly detectable." Without this baseline, malware C2 can simply float with the current alongside an organization's regular mail flow.
Perhaps counterintuitively, the easiest way to detect these ultra-stealthy implants is by simply looking for them.
"It's straightforward on any Linux system where you have shell access or an agent," Beek says. "Look for processes whose executable has been deleted (they show a '(deleted)' suffix under /proc), unexpected raw packet sockets, and known dropper artifacts such as the /HDD/ms6x2xTo64/ directory. Restricting management access to edge devices and monitoring outbound port 25 from anything that isn't a mail service are also routine controls for a mature security team."
Nate Nelson is a journalist and award-winning scriptwriter. In addition to Dark Reading he writes for Darknet Diaries, the most popular show in cybersecurity across all media.
He began his career as a freelancer, ghostwriting Forbes and CNBC op-eds for executives in tech and finance. Then he transitioned to journalism at Threatpost, where he covered cybersecurity news and trends. Throughout those years he co-created a cybersecurity podcast, Malicious Life, which in its day climbed into the Top 20 technology podcasts charts on Apple Podcasts and Spotify.
He holds degrees from New York University and Bard College. As a born and bred New Yorker, he enjoys a superiority complex, but is polite enough to keep it to himself.
Want more Dark Reading stories in your Google results?
The State of Cloud Security: The Latest Challenges
The State of Cloud Security: The Latest Challenges
How Organizations Are Managing Incident Response
How Organizations Are Managing Incident Response
How Enterprises Are Developing Secure Applications
How Enterprises Are Developing Secure Applications
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Essential News & Insights from Black Hat USA 2025
Essential News & Insights from Black Hat USA 2025
The Frontier AI Threat: Closing the Mobile Gap in Your Exposure Management Strategy
The Frontier AI Threat: Closing the Mobile Gap in Your Exposure Management Strategy
Static Analysis, Smarter Triage, Agentic Depth: A Practical AppSec Stack for AI-Driven Development
Static Analysis, Smarter Triage, Agentic Depth: A Practical AppSec Stack for AI-Driven Development
Effective Alert Triage: Reducing Noise and Finding Real Threats
Effective Alert Triage: Reducing Noise and Finding Real Threats
Cybersecurity Outlook 2027
Cybersecurity Outlook 2027
Threat Exposure Analytics: Measuring and Communicating Security Risk
Threat Exposure Analytics: Measuring and Communicating Security Risk
Hackers Target Cybersecurity Firm Outpost24 in 7-Stage Phish
Iran's Cyber-Kinetic War Doctrine Takes Shape
React2Shell Exploits Flood the Internet as Attacks Continue
Chinese Gov't Fronts Trick the West to Obtain Cyber Tech
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
