Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan
AI-summarised brief · reviewed before publication
Linux backdoors targeting telecom and network appliances in South Korea and Taiwan disguise their traffic as email security tools SpamSniper and ShareTech to evade detection. Rapid7 identified new BPFDoor variants that mimic SpamSniper’s PID file and rotate through ten Linux daemon names, while a separate implant, AVERAT, is delivered via an ELF dropper that encrypts itself with a key derived from “ShareTech.” The malware uses BPF to trigger on HTTPS POST requests, TinyShell for command execution, and SMTP for C2, demonstrating adaptive evasion tactics.
💡 Why It Matters
- · The attackers’ use of legitimate product names and standard telecom protocols shows a sophisticated strategy to bypass both signature‑based and behavioral defenses, raising the threat level for critical infrastructure operators in the region.