In a recent cyber threat operation, Linux backdoors have been discovered targeting telecom and network appliances in South Korea and Taiwan. These backdoors cleverly disguise their activities by impersonating well-known email security products such as SpamSniper and ShareTech, which integrate seamlessly into enterprise environments. By mimicking these legitimate processes, the malicious software blends in, making detection challenging for cybersecurity analysts.
Rapid7's investigation uncovered that the backdoors, including a new variant of BPFDoor and a Linux implant named AVERAT, are part of a sophisticated campaign. The threat actors behind this operation have a history of targeting telecom providers in the Middle East and Asia, attributed to a group known as Red Menshen. These backdoors exploit the Berkeley Packet Filter (BPF) functionality to inspect network traffic, triggering malicious behavior only upon receiving specific packets. This technique allows them to evade conventional detection methods.
BPFDoor variants in South Korea impersonate the PID file of SpamSniper, rotating through various Linux daemon names to remain unnoticed. Additionally, these backdoors utilize TinyShell for command execution, linked to China-based threat actor clusters. The campaign also sees the use of a Rekoobe-based backdoor intercepting traffic, further complicating detection efforts.
In Taiwan, a new Linux implant called AVERAT utilizes a dropper to install itself. It communicates with its command-and-control server using SMTP, masking its malicious activities. This implant is strategically placed within the ShareTech appliance's directory, using encryption derived from the appliance's name to evade scrutiny.
Organizations are advised to scrutinize unexpected network activities and implement stringent access controls to protect against these evolving threats. The campaign highlights the need for constant vigilance as threat actors refine their tactics to exploit secure email gateways for intelligence collection.

