www.rapid7.com New Linux Backdoors Exploit Telecoms via SMTP Traffic
Article Content
- •Linux backdoors exploit telecom devices in South Korea and Taiwan.
- •Backdoors disguise traffic as legitimate email to evade detection.
- •Rapid7 recommends monitoring outbound connections on affected devices.
Linux backdoors targeting telecom and network-edge devices in South Korea and Taiwan have been discovered, masquerading as legitimate email traffic. Rapid7 reported on October 2, 2026, that these backdoors include a BPFDoor variant and a BPF Rekoobe build, alongside a dropper and six AVERAT implant builds. The AVERAT implant operates over TCP port 25, using SMTP commands to blend in with normal email traffic, making detection difficult. The implants can execute commands like file transfers and process terminations, and they check in every 600 to 699 seconds. The BPF Rekoobe variant disguises its traffic by mimicking the processes of a South Korean anti-spam product. Rapid7 noted that compromised devices in Taiwan were used as relays, matching profiles in a prior CISA advisory on covert networks. Investigation and mitigation recommendations have been issued, focusing on monitoring unexpected outbound connections and restricting management access to vulnerable devices.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track BPFDoor in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What devices are affected?
How do these backdoors operate?
What should organizations do?
Continue Reading
New Linux Malware Mimics Asian Email Security Appliances Researchers have uncovered sophisticated Linux malware that closely imitates Korean and Taiwanese network edge appliances, making detection challenging. The malware includes backdoors such as BPFdoor and Rekoobe, which disguise themselves as legitimate processes, specifically targeting the popular SpamSniper anti-spam…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…