Skip to content
New Linux Backdoors Exploit Telecoms via SMTP Traffic

New Linux Backdoors Exploit Telecoms via SMTP Traffic

First seen 5 Oct 2026, 16:26 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 17:06 UTC
  • •Linux backdoors exploit telecom devices in South Korea and Taiwan.
  • •Backdoors disguise traffic as legitimate email to evade detection.
  • •Rapid7 recommends monitoring outbound connections on affected devices.

Linux backdoors targeting telecom and network-edge devices in South Korea and Taiwan have been discovered, masquerading as legitimate email traffic. Rapid7 reported on October 2, 2026, that these backdoors include a BPFDoor variant and a BPF Rekoobe build, alongside a dropper and six AVERAT implant builds. The AVERAT implant operates over TCP port 25, using SMTP commands to blend in with normal email traffic, making detection difficult. The implants can execute commands like file transfers and process terminations, and they check in every 600 to 699 seconds. The BPF Rekoobe variant disguises its traffic by mimicking the processes of a South Korean anti-spam product. Rapid7 noted that compromised devices in Taiwan were used as relays, matching profiles in a prior CISA advisory on covert networks. Investigation and mitigation recommendations have been issued, focusing on monitoring unexpected outbound connections and restricting management access to vulnerable devices.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-02
Rapid7 publishes findings
Rapid7 reported on newly discovered Linux backdoors targeting telecoms in South Korea and Taiwan, detailing their methods and impact.
Infosecurity-Magazine
2026-10-05
Articles published
Both Infosecurity-Magazine and Rapid7 published articles on the backdoors, highlighting their stealthy operations and impact on telecom infrastructure.
Rapid7

More articles in this cluster (2)

Following this threat?

Track BPFDoor in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What devices are affected?
Telecom and network-edge appliances in South Korea and Taiwan, including specific models like Synology NAS and Dahua video recorders.
How do these backdoors operate?
They disguise their traffic as legitimate email using SMTP commands over TCP port 25, making detection challenging.
What should organizations do?
Investigate unexpected outbound connections and restrict access to management interfaces on vulnerable devices.