Skip to content
Stealthy Linux Backdoors Target Telecoms in South Korea and Taiwan

Stealthy Linux Backdoors Target Telecoms in South Korea and Taiwan

First seen 5 Oct 2026, 16:26 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 6, 2026 at 07:27 UTC
  • •New Linux backdoors BPFDoor and AVERAT target telecom appliances in South Korea and Taiwan.
  • •Malware disguises traffic as legitimate email, making detection challenging.
  • •Rapid7 recommends monitoring for unusual outbound connections and restricting device access.

Rapid7 has reported new Linux backdoors, specifically BPFDoor and AVERAT, targeting telecom and network-edge appliances in South Korea and Taiwan. These backdoors disguise their malicious traffic as legitimate email using SMTP on TCP port 25, making detection difficult on mail security gateways. The malware can perform various actions, including file transfers and establishing multiple shell sessions. AVERAT connects to hardcoded addresses on compromised devices, which include Synology NAS and Dahua video recorders, potentially forming operational relay box networks. The attack leverages process spoofing by mimicking legitimate software like SpamSniper. Rapid7 recommends investigating unusual outbound connections and restricting access to affected devices. Attribution to state-sponsored actors is ongoing, with no confirmed overlap with known networks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-02
Rapid7 reports on new Linux backdoors
Rapid7 identifies BPFDoor and AVERAT targeting telecom systems in South Korea and Taiwan, detailing their stealthy tactics.
Infosecurity Magazine
2026-10-05
Multiple outlets publish findings
Msspalert and Broadcom report on the same Rapid7 findings, confirming the ongoing threat to telecom infrastructure.
Msspalert

More articles in this cluster (4)

Following this threat?

Track BPFDoor and Oracle in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What systems are affected?
Telecom and network-edge appliances in South Korea and Taiwan, including Synology NAS and Dahua video recorders.
How does the malware evade detection?
It disguises its traffic as legitimate email using SMTP on TCP port 25, making it hard to distinguish from normal operations.
What should organizations do to protect themselves?
Investigate unusual outbound connections and restrict management access to affected devices.