Malicious Linux Backdoors Mimic Asian Email Security Products, Threaten Global Organizations
Cybersecurity researchers have uncovered a trio of highly sophisticated Linux backdoors that infiltrate and mimic legitimate edge solutions from prominent Asian email security vendors. These malware implants, identified as BPFdoor, Rekoobe, and AVERAT, exhibit an uncanny ability to imitate the characteristics of popular network edge appliances, making it difficult for even seasoned security professionals to detect their presence.
The most concerning aspect of these backdoors is their ability to mimic the filenames, firewall-allowed traffic, and operating habits of well-known Asian email security products. This level of sophistication allows them to blend seamlessly into the environment, increasing the chances of successful infiltration and data exfiltration. The researchers at Rapid7 Intelligence, who discovered these backdoors, have documented two separate campaigns involving these malware implants.
The first campaign revolves around new variants of BPFdoor, a notorious Linux backdoor known for its stealthy behavior. BPFdoor has been adapted to mimic the appearance and behavior of SpamSniper, a South Korean anti-spam software used by over 6,000 organizations worldwide. In addition to mimicking SpamSniper, some BPFdoor samples disguise themselves as background processes found in Oracle-backed telecom subscriber and provisioning platforms.
The second campaign involves Rekoobe, another longstanding Linux RAT, which has been masquerading as SpamSniper. This new variant of Rekoobe also copies the legitimate software’s Process ID (PID) file, system services, and commonly used Linux services. Furthermore, Rekoobe mimics BPFdoor by adopting its passive Berkeley Packet Filtering (BPF) activation technique.
In a separate campaign, researchers discovered AVERAT, a novel modular RAT that shares cryptography routines with a malware dropper belonging to seemingly a distinct operation. The ShareTech Information appliance dropper, which imitates a Taiwanese mail security vendor, installs itself and then waits 10 seconds before deleting all malicious files, leaving behind only running processes to limit evidence of the infection.
The fact that these backdoors are targeting Asian email security products suggests that they are being aimed at organizations in the Asia-Pacific region. This is further supported by the popularity of SpamSniper among Asian businesses, with over 6,000 organizations using it as of July 2023.
Organizations worldwide must take immediate action to protect themselves from these sophisticated threats. The key takeaway from this discovery is that even well-established security solutions are not immune to being imitated and exploited by malicious actors. To mitigate the risk, we recommend that IT teams:
* Regularly review and update their network edge configurations to ensure they align with industry best practices
* Implement robust monitoring and logging capabilities to detect anomalies in system behavior
* Conduct thorough vulnerability assessments to identify potential entry points for these backdoors
* Provide ongoing security awareness training to employees to educate them on the latest threats and tactics used by attackers
By taking a proactive approach to cybersecurity, organizations can reduce their exposure to these sophisticated threats and maintain the integrity of their networks.
Source: Dark Reading — 2026-10-02