What's Happening?
Researchers at Rapid7 have identified sophisticated Linux backdoors targeting telecom and network-edge appliances, primarily in South Korea and Taiwan. These new malware variants employ stealthy tactics to evade detection. One implant, named AVERAT, utilizes
Transmission Control Protocol (TCP) port 25 and the Simple Mail Transfer Protocol (SMTP) to communicate, making its outbound traffic appear as legitimate email on mail security gateways. AVERAT is capable of file transfers, process termination, establishing multiple shell sessions, and creating proxy or port-forwarding channels. Other variants, including BPFDoor and BPF Rekoobe, impersonate legitimate services like SpamSniper, an anti-spam product, or mimic processes on Oracle-based telecom platforms. Compromised devices, such as Synology NAS, small-business appliances, and Dahua video recorders, are being used as relays, potentially forming operational relay box (ORB) networks.
Why It's Important?
The emergence of these highly evasive Linux backdoors poses a significant threat to network security, particularly for organizations relying on telecom and network-edge appliances. By disguising malicious traffic as legitimate email and masquerading as essential system services, these backdoors can bypass traditional security measures, making detection extremely difficult. The ability to establish proxy networks from compromised devices allows attackers to obscure their origins and conduct further malicious activities, including data exfiltration, command and control, or launching subsequent attacks. This sophisticated evasion technique highlights a growing challenge for cybersecurity professionals, who must adapt their detection strategies to identify more subtle indicators of compromise beyond signature-based methods. The targeting of critical infrastructure components like telecom appliances also raises concerns about potential disruptions to essential services.
What's Next?
Rapid7 advises organizations to proactively investigate unusual packet sockets, outbound port 25 connections originating from non-mail services, and processes that appear to be masquerading as system daemons. Restricting management access to edge appliances is also recommended to mitigate the risk of compromise. Cybersecurity vendors will likely update their detection capabilities to identify these new evasion techniques. Network administrators and security teams will need to enhance their monitoring for behavioral anomalies rather than just known signatures. The ongoing evolution of these stealthy malware tactics suggests a continuous arms race between attackers and defenders, requiring constant vigilance and adaptation in cybersecurity strategies.
Beyond the Headlines
The sophistication of these Linux backdoors points to a broader trend in cyber warfare where attackers are increasingly focusing on stealth and persistence within compromised networks. The use of legitimate protocols and service impersonation represents a significant leap in evasion tactics, moving beyond simple obfuscation. This development could lead to a re-evaluation of network security architectures, emphasizing deeper packet inspection, behavioral analytics, and zero-trust principles for all network traffic, even that which appears benign. The potential for these compromised devices to form ORB networks also raises concerns about their use in larger, state-sponsored cyber operations or organized cybercrime, making attribution and mitigation even more challenging. This highlights the critical need for robust security practices across the entire digital supply chain, especially for IoT and edge devices that often have less stringent security controls.













