Scworld New Linux Malware Mimics Asian Email Security Appliances
Article Content
- •New Linux malware mimics legitimate email security appliances to evade detection.
- •BPFdoor and Rekoobe backdoors target SpamSniper software used by thousands.
- •AVERAT malware specifically targets Taiwanese mail security vendor ShareTech Information.
Researchers have uncovered sophisticated Linux malware that closely imitates Korean and Taiwanese network edge appliances, making detection challenging. The malware includes backdoors such as BPFdoor and Rekoobe, which disguise themselves as legitimate processes, specifically targeting the popular SpamSniper anti-spam software used by over 6,000 organizations. Another tool, AVERAT, is linked to attacks on Taiwanese mail security vendor ShareTech Information. These backdoors exploit TCP Port 25 to blend command-and-control traffic with normal email communications, complicating detection efforts. The campaigns are characterized by their advanced mimicry techniques, replicating filenames and operational habits of the legitimate software they impersonate. The threat landscape is particularly concerning for organizations in the Asia-Pacific region, where these appliances are prevalent. Current status indicates ongoing research and monitoring of these threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track BPFDoor in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which systems are affected by the malware?
How does the malware evade detection?
What should organizations do to protect themselves?
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…