Skip to content
New Linux Malware Mimics Asian Email Security Appliances

New Linux Malware Mimics Asian Email Security Appliances

First seen 4 Oct 2026, 04:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 06:06 UTC
  • •New Linux malware mimics legitimate email security appliances to evade detection.
  • •BPFdoor and Rekoobe backdoors target SpamSniper software used by thousands.
  • •AVERAT malware specifically targets Taiwanese mail security vendor ShareTech Information.

Researchers have uncovered sophisticated Linux malware that closely imitates Korean and Taiwanese network edge appliances, making detection challenging. The malware includes backdoors such as BPFdoor and Rekoobe, which disguise themselves as legitimate processes, specifically targeting the popular SpamSniper anti-spam software used by over 6,000 organizations. Another tool, AVERAT, is linked to attacks on Taiwanese mail security vendor ShareTech Information. These backdoors exploit TCP Port 25 to blend command-and-control traffic with normal email communications, complicating detection efforts. The campaigns are characterized by their advanced mimicry techniques, replicating filenames and operational habits of the legitimate software they impersonate. The threat landscape is particularly concerning for organizations in the Asia-Pacific region, where these appliances are prevalent. Current status indicates ongoing research and monitoring of these threats.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-02
Malware discovery reported
Researchers identified sophisticated Linux implants mimicking Asian email security appliances, complicating detection efforts.
Darkreading
2026-10-03
Further details on malware campaigns
Scworld reported on the overlapping campaigns involving BPFdoor, Rekoobe, and AVERAT targeting specific email security systems.
Scworld

More articles in this cluster (2)

Following this threat?

Track BPFDoor in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which systems are affected by the malware?
The malware targets Linux-based email security appliances, particularly SpamSniper and ShareTech Information products.
How does the malware evade detection?
It mimics legitimate processes and blends command-and-control traffic with normal email communications, complicating detection.
What should organizations do to protect themselves?
Organizations should monitor network traffic for unusual patterns and ensure their email security systems are updated and properly configured.