Breaking
Cyber CrimeDeveloping Story

Backdoors Hide Behind Email Security Brands

Rapid7 says Linux implants in South Korea and Taiwan impersonate SpamSniper and ShareTech to slip past defenders.

··1 hour ago·8 min read
Computer screen displaying lines of code
Photo by Jakub Żerdzicki on Unsplash

Linux backdoors planted on telecom and network appliances in South Korea and Taiwan are not just hiding in the background. According to research from Rapid7, they are borrowing the identities of the email security products already running on those systems, making themselves look like ordinary pieces of the vendor stack.

The trick matters because it targets the exact layer defenders rely on to spot trouble. By naming malicious files after a trusted anti-spam tool or an appliance add-on, the operators give their implants a reason to exist on the machine — and a reason for a busy analyst to look the other way.

Naming Games as a Defense Tactic

Threat actors have long named malware after legitimate operating system components or processes as a way to avoid detection. A malicious binary that looks like a routine system service may appear less conspicuous next to real processes, and it can borrow a false sense of trust that survives a quick visual inspection.

The artifacts Rapid7 examined go further than filename mimicry. They assume the identities of email security products that are widely used in enterprise environments in South Korea and Taiwan, according to the vendor's research.

SpamSniper, from vendor Jiran Group, is advertised as "Korea's leading email security solution" that defends organizations against spam, malware, and server attacks. ShareTech, whose appliance software appears in the same campaign, is another recognizable name in the regional security stack. Both are the kind of tool that an administrator would expect to find running on a mail-adjacent appliance.

Three Distinct Implants at Work

The malicious artifacts Rapid7 documented include a new BPFDoor variant and a BPF Rekoobe build used against South Korean targets, plus a previously unreported Linux implant called AVERAT that is delivered via a dropper and deployed against Taiwanese appliances.

Each one leans on regional context. The BPFDoor variants seen against South Korean systems impersonate the PID file of SpamSniper and rotate through ten Linux daemon names, Rapid7 said. Across the samples, each component adopts names and conventions designed to look unremarkable in the environment it targets.

The Rekoobe-based BPF backdoor observed alongside the activity intercepts TCP, UDP, and SCTP IPv4 traffic as well as UDP IPv6 traffic where the source and destination ports equal 25. It names its processes after components of SpamSniper, again fitting the local software profile.

How BPFDoor Quietly Waits

BPFDoor, in broad terms, abuses Berkeley Packet Filter functionality to inspect incoming network traffic. It stays dormant until it sees a magic packet, which is the signal that tells the implant to wake up and start behaving like a backdoor. That design means the implant does not listen on a port or announce itself; it watches traffic that is already flowing past.

Once triggered, the BPFDoor sample launches a TinyShell session and supports commands for interactive shell access, uploads, and downloads. The use of TinyShell has previously been attributed to China-nexus clusters including Liminal Panda, UNC3886 (also known as Fire Ant), and Velvet Ant — groups that have singled out telecom networks and edge devices.

These samples, Rapid7 said, show BPFDoor operating as a modular framework that adapts to the telecom layer it targets, integrating TinyShell and Rekoobe logic to support exfiltration.

Responding to Published Signatures

The appearance of a new BPFDoor version is itself a signal. It indicates that the operators behind the malware are actively refining and retooling their arsenal in response to public disclosures, rather than abandoning tooling that defenders have learned to recognize.

Rapid7 described the shift in tactics directly. Once security vendors wrote static network signatures such as Suricata and Snort rules to detect the Layer 4 anomalies, the operators began targeting the edge proxies. By wrapping the magic packet in standard HTTPS POST requests and relying on SSL offloading common in telecom environments, the trigger can be delivered to a BPFDoor-infected node in a way that may evade conventional deep packet inspection.

That is a response to defenders getting better. Detection work pushed the operators toward the network edge, where encrypted traffic and offloaded TLS are normal parts of the architecture.

The Oracle-Looking Sample

Not every sample spoofs an email security product. Another artifact sets its process name to "ora_ppmond," mimicking the naming convention associated with Oracle-backed telecom subscriber and provisioning platforms. The name appears to reference ora_pmon_*, which represents the Process Monitor background process of an Oracle Database instance.

The choice is not arbitrary. On a telecom system, a process that looks like part of an Oracle database deployment is far less likely to raise questions than a binary with an unfamiliar name. It is the same regional disguise strategy applied to a different piece of the stack.

AVERAT and Its SMTP Channel

The AVERAT implant takes the disguise theme in a more deliberate direction. The dropper observed in an overlapping campaign is an ELF binary that acts as a local installer for AVERAT, a modular implant that uses the Simple Mail Transfer Protocol for command-and-control and to obscure its malicious activity.

The dropper is located within the ShareTech appliance's "/addpkg/sbin/" add-on package directory. It derives its encryption key from the string "ShareTech" and uses that key to decrypt a shell script responsible for staging and executing two binaries: "ntpdate," which is the dropper itself, and "udevds," which is the AVERAT payload. The two files are deleted 10 seconds later.

AVERAT then periodically polls a C2 server at "mx.zxopfds[.]com" over TCP port 25 every 600 to 699 seconds. The server details and beacon interval are extracted from an encrypted configuration, so the implant does not carry obvious hardcoded indicators in plain sight.

Port 25 is the standard SMTP port. Traffic to it from an appliance is far less unusual than a beacon to an unknown host on an odd port, which is presumably the point.

A Long List of Remote Commands

The backdoor supports a long list of command codes, according to Rapid7's analysis. They cover everything from reconnaissance to full remote control of the appliance:

  • 20, to enumerate directory contents
  • 21, to download a file from the host, with resume support
  • 22, to upload a file to the host in chunks
  • 25, to recursively delete a file or directory tree
  • 30, to recursively walk a directory tree
  • 629, to enumerate running processes with command lines
  • 632, to terminate a process (SIGTERM)
  • 842, to overwrite the C2 host and port tables at runtime
  • 912, to open an interactive shell session and up to 10 concurrent sessions
  • 914, to write a command into an open shell session
  • 916, to reboot the appliance
  • 1010, to load or unload a shared object (*.so) module, extending the implant functionality
  • 1576, to set the callback interval and persist it to database
  • 1618, to open a proxy or port-forward channel through the appliance
  • unknown, to close the socket and terminate the process immediately

The command set shows an implant built for sustained access rather than a quick smash-and-grab. It can pull files, push files, wipe traces, open shells, load additional modules, and turn the appliance into a relay.

An ORB-Shaped Infrastructure

AVERAT's C2 infrastructure matches the device-class profile typically associated with an Operational Relay Box network, according to Rapid7. The company added that there is no evidence the infrastructure is part of any known ORB operation, naming LapDogs (also known as UAT-7810), SPACEHOP, and FLORAHOX as examples of such networks.

The distinction is worth keeping straight. The network looks like the kind of relay setup used by ORB operators, but attribution to a specific known cluster is not supported by the evidence Rapid7 presented.

What Defenders Are Told to Check

Rapid7's recommendations for organizations are concrete and mostly centered on noticing things that should not be there. The company advises reviewing unexpected raw packet sockets and BPF filters on Linux systems that do not require packet capture, since a passive implant depends on exactly that capability.

It also recommends auditing outbound TCP port 25 connections from processes that are not mail services, scanning for processes posing as common daemons, and restricting management access to routers, DVRs, and other edge appliances. Each of those steps maps to the behavior observed in these samples.

The port 25 audit is a direct counter to AVERAT's beaconing. The daemon-name scan is a counter to the SpamSniper and "ora_ppmond" spoofing. Restricting management access narrows the surface that edge appliances present in the first place.

A Pattern Around Email Gateways

The findings show threat actors leveraging the privileged position occupied by secure email gateways for intelligence collection. Those systems sit in front of organizational mail, which makes them a natural place to watch traffic and collect information.

This is not the first time the pattern has appeared. In 2023, a China-nexus threat actor codenamed UNC4841 was observed exploiting two vulnerabilities in Barracuda Email Security Gateway appliances — CVE-2023-2868 and CVE-2023-7102 — to deliver persistent backdoors.

What ties the current samples together, in Rapid7's description, is regionalized disguise. Each sample is aware of the vendor's software running on the targeted systems and implements process spoofing accordingly. Passive BPF implants avoid conventional port scans, while outbound beacons hide inside ordinary DNS, TCP, and traffic. The actors, the company said, are leveraging SMTP to stay under the radar.

"The common thread is regionalized disguise: each sample is aware of the vendor's software running on the targeted systems and implements process spoofing accordingly."

— Rapid7, in its analysis of the BPFDoor and AVERAT samples

Why This Matters for Appliance Owners

The immediate consequence is that trust in a product name is no longer a useful filter. An administrator who sees a SpamSniper PID file or a ShareTech add-on directory entry has, until now, had little reason to look twice. The campaigns Rapid7 described are built precisely on that habit, which means the same instinct that keeps daily operations moving is the one being exploited.

For organizations running mail-adjacent appliances, especially in telecom and network environments, the practical effect is that detection has to move beyond names and ports. The checks Rapid7 recommends — raw packet sockets without a capture need, SMTP traffic from non-mail processes, daemon impersonation, and unnecessary management exposure — are aimed at behavior rather than labels.

There is also a broader implication for edge devices. These appliances are attractive targets because they sit outside the typical endpoint security perimeter, and the shift toward wrapping trigger traffic in ordinary HTTPS POST requests suggests defenders should expect more activity to blend into the encrypted traffic these devices already handle. For businesses that rely on email security gateways, the value of knowing exactly what should be running on those systems — and being able to account for every process and outbound connection — is higher than it might appear from the outside.

#linux malware#bpfdoor#averat#rapid7#cyber espionage#email security

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories