www.rapid7.com Stealthy Linux Backdoors Target Telecoms in South Korea and Taiwan
Article Content
- •New Linux backdoors BPFDoor and AVERAT target telecom appliances in South Korea and Taiwan.
- •Malware disguises traffic as legitimate email, making detection challenging.
- •Rapid7 recommends monitoring for unusual outbound connections and restricting device access.
Rapid7 has reported new Linux backdoors, specifically BPFDoor and AVERAT, targeting telecom and network-edge appliances in South Korea and Taiwan. These backdoors disguise their malicious traffic as legitimate email using SMTP on TCP port 25, making detection difficult on mail security gateways. The malware can perform various actions, including file transfers and establishing multiple shell sessions. AVERAT connects to hardcoded addresses on compromised devices, which include Synology NAS and Dahua video recorders, potentially forming operational relay box networks. The attack leverages process spoofing by mimicking legitimate software like SpamSniper. Rapid7 recommends investigating unusual outbound connections and restricting access to affected devices. Attribution to state-sponsored actors is ongoing, with no confirmed overlap with known networks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track BPFDoor and Oracle in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What systems are affected?
How does the malware evade detection?
What should organizations do to protect themselves?
Continue Reading
New Linux Malware Mimics Asian Email Security Appliances Researchers have uncovered sophisticated Linux malware that closely imitates Korean and Taiwanese network edge appliances, making detection challenging. The malware includes backdoors such as BPFdoor and Rekoobe, which disguise themselves as legitimate processes, specifically targeting the popular SpamSniper anti-spam…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…