New Linux Backdoors Disguise Malicious Traffic as Email and Legitimate Services
Researchers at Rapid7 have identified sophisticated Linux backdoors targeting telecom and network-edge appliances, primarily in South Korea and Taiwan. These new malware variants employ stealthy tactics to evade detection. One implant, named AVERAT, utilizes Transmission Control Protocol (TCP) port 25 and the Simple Mail Transfer Protocol (SMTP) to communicate, making its outbound traffic appear as legitimate email on mail security gateways. AVERAT is capable of file transfers, process termination, establishing multiple shell sessions, and creating proxy or port-forwarding channels. Other variants, including BPFDoor and BPF Rekoobe, impersonate legitimate services like SpamSniper, an anti-spam product, or mimic processes on Oracle-based telecom platforms. Compromised devices, such as Synology NAS, small-business appliances, and Dahua video recorders, are being used as relays, potentially forming operational relay box (ORB) networks.