Malicious Linux Implants Mimic Asian Mail Security Products

Malicious Linux Implants Mimic Asian Mail Security Products

In a disturbing trend that highlights the cunning and adaptability of cyber attackers, researchers have uncovered a trio of backdoors that convincingly mimic popular Asian email security appliances on Linux systems. These implants are so sophisticated that they even replicate the filenames, firewall-allowed traffic, and operating habits of their legitimate counterparts, making it extremely difficult for security professionals to detect them.

According to research from Rapid7 Intelligence, these malicious software tools have been designed to target organizations in Asia-Pacific countries, where email security appliances like SpamSniper are widely used. The most egregious example is the “BPFdoor” backdoor, which has been adapted to mimic the behavior of a South Korean anti-spam software called SpamSniper. This malware lays dormant on infected systems, waiting for an activation code embedded in incoming HTTPS requests before springing into action.

What’s more alarming is that BPFdoor has been shown to propagate data to specific computers within target organizations by inserting malicious code into innocuous ICMP pings. This technique allows Chinese handlers to continue spying on global telecommunications companies without raising suspicion. The newest variants of BPFdoor even disguise themselves as background processes in Oracle-backed telecom subscriber and provisioning platforms.

Another Linux RAT, “Rekoobe,” has been found masquerading as SpamSniper, part of the same general campaign. This malware takes its mimicry to an extreme level by copying legitimate software’s Process ID (PID) file, system services, and commonly used Linux services. Rekoobe also mimics BPFdoor’s passive Berkeley Packet Filtering activation technique.

The reason these programs chose SpamSniper as their inspiration is not a coincidence; it indicates which sorts of targets they’re being aimed at. As of July 2023, over 6,000 organizations had installed SpamSniper, according to Japanese B2B search platform IPROS. The vendor, Jiran Group, boasts about supplying customers across the Asia-Pacific region, including central government ministries and public institutions in South Korea.

In a separate campaign, researchers have identified a malware dropper that adopts the identity of a ShareTech Information appliance, a Taiwanese mail security vendor that services large enterprises, educational institutions, and government entities. This dropper installs two programs: itself, in a loop, and AVERAT, a mostly straightforward modular RAT. AVERAT is designed to provide attackers with remote access to infected systems.

The implications of these findings are dire. With the rise of sophisticated malware that can convincingly mimic legitimate software, security professionals must be vigilant in detecting and preventing such attacks. One crucial takeaway is the importance of regularly updating Linux systems, as well as monitoring network traffic for suspicious activity. Furthermore, organizations should exercise caution when installing email security appliances from vendors based in Asia-Pacific countries, especially if they’re used by multiple government institutions or large enterprises.

By staying informed about these emerging threats and adapting our defenses accordingly, we can mitigate the impact of these malicious implants and prevent them from causing harm to our critical infrastructure.


Source: Dark Reading — 2026-10-02