AVERAT and BPFDoor: SMTP-cloaked Linux implants mimic South Korean and Taiwanese mail-security appliances
By Sethu Satheesh · 6 Oct 2026 · 15 min read
Threat Actor: Unknown (unattributed; Rapid7 assesses infrastructure consistent with China-nexus ORB patterns) · Target: Telecom and network-edge / mail-security appliance operators in South Korea and Taiwan
Source: www.rapid7.com
Executive Summary
On October 2, 2026, Rapid7 Intelligence published a technical report describing a set of Linux implants built to disappear into the software and device conventions of the telecom and mail-security environments they target.1 The set spans a newly observed BPFDoor variant and a BPF-enabled Rekoobe build seen against South Korean systems, plus a dropper and six builds of a modular implant Rapid7 tracks as AVERAT, deployed against Taiwanese appliances.1 The report was the first piece of research released under Rapid7 Intelligence, a newly launched research function.2
The unifying tradecraft is regionalized disguise. The South Korean cluster impersonates the PID file and daemon names of SpamSniper, a Korean anti-spam product, while one AVERAT dropper derives its own AES key from the string ShareTech, the name of a Taiwanese mail-security vendor.1 The headline evasion is the abuse of TCP port 25: both the BPF Rekoobe build and AVERAT send command-and-control traffic over SMTP, so that on a mail gateway — whose core function is to send mail to arbitrary mail exchangers — the implant's outbound traffic is indistinguishable from legitimate work in flow records.13 AVERAT speaks real SMTP (EHLO, then STARTTLS) before switching to its own hand-built encrypted session, supports file transfer, process termination, up to ten concurrent interactive shells, and proxy/port-forwarding, and beacons every 600 to 699 seconds.1
Rapid7 recovered three command-and-control addresses from AVERAT configurations, all compromised consumer and small-business customer-premises equipment — a Synology NAS at a fuel retailer, an obsolete NetKlass SMB appliance, and a Dahua DVR — sitting in Chunghwa Telecom's HiNet address space (AS3462) across three Taiwanese cities.1 Each also runs operator-installed PPTP, making it dual-purpose: an outbound relay for SMTP-disguised implant traffic and an inbound VPN foothold into the host's own LAN. Rapid7 assesses this device-class profile matches what CISA, NCSC-UK and partner agencies described in their April 2026 joint advisory (AA26-113A) as the building blocks of China-nexus covert, or operational relay box (ORB), networks.1
The report's most important qualification is about attribution, and it matters because of the lineage of the tooling. BPFDoor has prior reporting linking it to a China-nexus actor, and Rapid7's own earlier (March 2026) BPFDoor investigation attributed that separate campaign to Red Menshen.45 For this SMTP campaign, Rapid7 explicitly declined to name an actor: it found no infrastructure or indicator overlap with any specific named ORB network (LapDogs/UAT-7810, SPACEHOP, or FLORAHOX), and said "specific attribution should remain an ongoing assessment."1 These are analyzed malware samples; Rapid7 does not disclose named, confirmed victim organizations, and the targeting is inferred from the vendors the implants mimic and the appliances they were built for.16
Verification of Claims
-
Claim: The campaign comprises a new BPFDoor variant, a BPF Rekoobe build, a dropper, and six AVERAT builds. → Verified → Rapid7's report and its indicators-of-compromise tables enumerate the samples: two SpamSniper-spoofing BPFDoor sniffers, two data-plane BPFDoor samples, one dual-port-25 BPF Rekoobe, one dropper, and six AVERAT builds, each with a distinct SHA-256.1 Infosecurity Magazine and MSSP Alert independently report the same counts.3
-
Claim: AVERAT and the Rekoobe build hide command-and-control inside SMTP on TCP port 25. → Verified → Rapid7 documents AVERAT issuing
EHLOandSTARTTLSon port 25 before its own encrypted session, and the Rekoobe build's 26-instruction BPF filter gating on source and destination ports both equal to 25.1 Dark Reading and Infosecurity Magazine describe the same mechanism.23 -
Claim: This SMTP/AVERAT campaign is attributed to China / Red Menshen. → Unverified → Rapid7 did not attribute this campaign to any named actor. It assessed only that the relay infrastructure matches a China-nexus ORB device-class pattern, found no overlap with any named ORB network, and said attribution remains an ongoing assessment.1 The China-nexus Red Menshen attribution belongs to Rapid7's separate, earlier (March 2026) BPFDoor investigation, not to this report.45
-
Claim: The three recovered C2 addresses are compromised third-party devices, not operator-owned servers. → Verified → Rapid7 states the three IPs "represent compromised CPE belonging to third-party victims rather than intentional operator assets," identifying a Synology NAS, a NetKlass SMB appliance, and a Dahua DVR, all in Chunghwa Telecom HiNet (AS3462).1
-
Claim: Named telecom victim organizations have been confirmed compromised. → Unverified → Rapid7 presents analyzed samples and infrastructure; it names no compromised customer organization and discloses no victim count. securityonline.info records "victim counts not disclosed," and targeting is inferred from the mimicked vendors (SpamSniper, ShareTech) and appliance classes.16
Timeline
| Date | Actor | Event | Source |
|---|---|---|---|
| 2021–2022 | — | BPFDoor publicly documented from 2021; its source code leaked in 2022, enabling many independent builds | 4 |
| March 26, 2026 | Rapid7 | Earlier Rapid7 BPFDoor investigation published, attributing a telecom espionage campaign to China-linked Red Menshen | 45 |
| April 2026 | CISA / NCSC-UK / partners | Joint advisory AA26-113A describes China-nexus covert/ORB networks built on end-of-life NAS, edge appliances and DVRs | 1 |
| October 2, 2026 | Rapid7 Intelligence | Report published on BPFDoor, BPF Rekoobe and six AVERAT builds using SMTP port 25 against South Korean and Taiwanese appliances | 12 |
| October 5, 2026 | Infosecurity Magazine | Independent coverage reports the six AVERAT builds and SMTP evasion; notes attribution remains ongoing | 3 |
Attack Anatomy
Initial access and delivery
Rapid7 does not reconstruct how the operators first reach the appliance; the dropper has no networking code and is "a local installer, run after access is already established."16 The AVERAT dropper (2bedc26d…) is an x86-64 ELF carrying four AES-128-ECB blobs keyed on the first sixteen bytes of SHA1("ShareTech"), that is 6C CA D5 17 0E 3D B8 17 B3 DF 52 E0 D9 71 B1 48 — the operators "seeded their own key derivation with the target vendor's name" (T1480, T1027.013).1
Fileless staging and persistence
Execution is gated on one precondition: the install branch fires only when /tmp/flag already exists and the script /HDD/ms6x2xTo64/updIptable.php does not.1 The dropper writes that shell script (a #!/bin/sh file under a .php extension) to the appliance's bulk-storage mount, chmods it 0777, and runs it via system(). The script copies /addpkg/sbin/update to /sbin/ntpdate and /addpkg/sbin/agetty to /sbin/udevds, launches each, and rm -rfs it ten seconds later while the process keeps running — so /proc/<pid>/exe resolves to (deleted) and nothing remains on disk to hash or quarantine (T1070.004, T1036.005).1 One payload is the dropper re-executing as ntpdate; finding the .php already present, it fails the gate and drops into a two-second watchdog that recreates execProcEnd and rewrites the script whenever either disappears. Persistence is implicit: /addpkg/sbin/ is the appliance's own add-on package directory, which the firmware very likely relaunches at boot (T1037).1
Passive magic-packet backdoors
The South Korean BPFDoor variant opens a raw PF_PACKET socket with a classic BPF filter using magic bytes 0x6693 (UDP), 0x4274 (TCP) and 0x7820 (ICMP); on a match it connects back if the password is gZbpx0, opens a bind shell if sT21xf, and otherwise defaults to a UDP knock (T1205, T1205.002).1 It carries the /var/run/spamsniper.pid mutex and rotates through ten spoofed daemon names (chronyd, polkitd, rsyslogd, crond, NetworkManager, tuned, watchdogd, python, scsi_tmf_6, charger_manager, kaluad_sync).1 A data-plane variant spoofs ora_ppmond, mimicking Oracle-backed telecom subscriber/provisioning platforms (HSS, OSS/BSS), and integrates Tiny Shell 'S'/'U'/'D' upload/download/shell logic.1 The BPF Rekoobe build (652508a9…) attaches a 26-instruction filter sniffing for TCP/UDP/SCTP IPv4 and UDP IPv6 with source and destination ports both equal to 25, protects strings with repeating-key XOR (uvTIgh47,@#R), and spoofs Sniper-platform process names such as /sniper/snipe/bin/snipe-smtpd (T1036.004).1 A src=25, dst=25 magic packet matches a mail appliance's own MTA-relay firewall rule and reaches the raw socket before stateful inspection.1
Command and control
AVERAT connects outbound to port 25, issues EHLO and STARTTLS, then begins a hand-built TLS session using a fixed 40-entry ClientHello compiled into the binary, with peer authentication deferred to an application-layer shared-secret handshake carrying the magic value 1571 (0x0623) (T1071.003, T1573.001).1 It beacons every 600–699 seconds — reporting hostname, current user, OS version, network interfaces and logged-in users — with the interval persisted to a hidden file /var/lib/.db (T1564.001, T1008).1 The command set (uint16 codes) includes directory enumeration (20), file download/upload with resume (21, 22), recursive delete (25), process enumeration and SIGTERM (629, 632), runtime overwrite of the C2 host/port tables (842), up to ten concurrent interactive shells (912, 914), reboot with sync() (916), load/unload of a shared-object module (1010), and a proxy/port-forward channel (1618) (T1059.004, T1105, T1041, T1090, T1489, T1529, T1129).1
Infrastructure and relay layer
The three recovered C2 addresses are compromised consumer/SMB CPE in Chunghwa Telecom HiNet (AS3462): a Synology NAS (59.125.211[.]65, Tainan), a NetKlass SMB appliance (122.116.138[.]33, Banqiao), and a Dahua DH-XVR5116HS-I3 recorder (1.34.200[.]85, Taoyuan) (T1584.008).1 All three return a byte-identical operator-installed PPTP banner on port 1723, making each a dual-purpose outbound relay and inbound VPN foothold (T1133).1
Loading diagram...
Threat Actor Profile
Name: Unknown — not attributed to a named actor by Rapid71 Aliases: None assigned to this campaign; the tooling (BPFDoor, Rekoobe) is shared, not actor-exclusive14 Attribution confidence: Rapid7 offers an infrastructure-level assessment only — the relay device-class profile matches the China-nexus covert/ORB pattern described in CISA/NCSC-UK joint advisory AA26-113A — while explicitly finding no overlap with any named ORB network (LapDogs/UAT-7810, SPACEHOP, FLORAHOX) and stating that "specific attribution should remain an ongoing assessment."1 Motivation: Assessed as long-term stealthy access and intelligence collection at the telecom network edge, consistent with espionage rather than disruption.12
The lineage is the reason attribution must be handled carefully. BPFDoor has been public since 2021 and its source code leaked in 2022, so many actors can build on it.4 A separate, earlier Rapid7 investigation published March 26, 2026 attributed a BPFDoor telecom-espionage campaign to the China-linked actor Red Menshen; SC Media and Cybersecurity Dive reported that attribution.45 That attribution applies to the earlier campaign, not to this October 2026 SMTP/AVERAT reporting, which Rapid7 left unattributed. Dark Reading's coverage of this report nonetheless states that the new variants let BPFDoor's "Chinese handlers" continue spying on global telecoms — a more confident framing than the primary research supports.2
The operator tradecraft Rapid7 highlights indicates maturity: the AVERAT dispatcher terminates the process on any unrecognized command code (raising the cost of probing), provisioning for ten concurrent shells suggests parallel operator access, and the reboot handler calls sync() before forcing a restart — the behavior of an operator who knows exactly which artifacts live in memory versus on disk.1
MITRE ATT&CK techniques (IDs verified live on attack.mitre.org):
| ID | Technique |
|---|---|
| T1584.008 | Compromise Infrastructure: Network Devices |
| T1133 | External Remote Services |
| T1480 | Execution Guardrails |
| T1037 | Boot or Logon Initialization Scripts |
| T1205 | Traffic Signaling |
| T1205.002 | Traffic Signaling: Socket Filters |
| T1059.004 | Command and Scripting Interpreter: Unix Shell |
| T1129 | Shared Modules |
| T1071.003 | Application Layer Protocol: Mail Protocols |
| T1573.001 | Encrypted Channel: Symmetric Cryptography |
| T1090 | Proxy |
| T1008 | Fallback Channels |
| T1036.004 | Masquerading: Masquerade Task or Service |
| T1036.005 | Masquerading: Match Legitimate Resource Name or Location |
| T1564.001 | Hide Artifacts: Hidden Files and Directories |
| T1070.004 | Indicator Removal: File Deletion |
| T1070.003 | Indicator Removal: Clear Command History |
| T1027.013 | Obfuscated Files or Information: Encrypted/Encoded File |
| T1686 | Disable or Modify System Firewall |
| T1105 | Ingress Tool Transfer |
| T1041 | Exfiltration Over C2 Channel |
| T1489 | Service Stop |
| T1529 | System Shutdown/Reboot |
OPSEC: Fileless execution (unlinked binaries), hidden .db state files, command-history and vim-log suppression (HISTFILE=/dev/null, VIMINIT="set viminfo="), hand-built TLS to frustrate library fingerprinting, runtime-changeable C2 port, and relay chaining through neglected CPE.1
Technical Indicators
c2_domains:
- mx.zxopfds[.]com
- spam.suwaccqi[.]com
- mx1.wwstifsteel[.]com
c2_ipv4:
- 59.125.211[.]65 # Synology NAS, Tainan (compromised relay CPE)
- 122.116.138[.]33 # NetKlass SMB appliance, Banqiao
- 1.34.200[.]85 # Dahua DH-XVR5116HS-I3 DVR, Taoyuan
c2_port: TCP/25 (SMTP)
sha256_averat_tw_cluster:
- 2bedc26d4b29b435c21962beed7db21188a0219a0d28334bba8b4fb1656d7b15 # dropper (/addpkg/sbin/update)
- bf8135f46ecedfe5bd06fcecbb2e721c2367ff765b18f4aa3f868e6597f49e47 # AVERAT
- 4925bcca085ec504f51191645da278d8e96698d91f3c6df44146336c697b4de8 # AVERAT
- a4379e115d3c4420f5d4b92561022d6e0897990e7297be65c033d47de68e6a6a # AVERAT
- 925c041807d4fb9dfe2ad84f963c2a4c60ea1289f6a0bdccbfb944478ffc2cf2 # AVERAT
- 2fe2dd402ee6f9c578fce6dd4b36daaa407e99133e5dd502f2afca80feb60150 # AVERAT
- a65048eb30661e27f8edc2dd8d8c77ec87faec1f1750f6e04e7ecaf069a32858 # AVERAT
sha256_sk_cluster:
- a37ea9897221d4495b538de72b74f2aa1d2ff09b7b6dcedd395aee58931adbf3 # SpamSniper BPFDoor sniffer
- 7e667ba5f9df912e02275d3cfe3809d16f822fe776f4035c84b118ebd925b1b5 # SpamSniper BPFDoor sniffer
- 652508a9cf40bee883dc0e5e219dfeba71fe7dac591d01c89f74c21f73b4963f # Rekoobe, dual port-25 BPF filter
- 4435fcd6862921092614dbeaa880e4192352984686ebcd98f0ba13ee8e226ef9 # data-plane BPFDoor
- a6f3b7f932761fb1fd5e74123f2482e36c65dd13e769af2ce08c65da195bfa7a # data-plane BPFDoor
host_artifacts:
- '/HDD/ms6x2xTo64/updIptable.php' # shell script under a .php extension
- '/HDD/ms6x2xTo64/execProcEnd' # watchdog marker, contains literal "end"
- '/tmp/flag' # dropper precondition gate
- '/var/lib/.db' # AVERAT state file (bf8135f4, 925c0418, 2fe2dd40)
- '/var/lib/.sencha' # AVERAT state file (4925bcca)
- '/var/lib/.us' # AVERAT state file (a4379e11)
- '/var/lib/.a' # AVERAT state file (a65048eb)
- '/var/run/spamsniper.pid' # BPFDoor mutex
- '/sbin/ntpdate' # staging name (dropper/watchdog)
- '/sbin/udevds' # staging name (AVERAT)
- '/addpkg/sbin/update' # dropper payload location
- '/addpkg/sbin/agetty' # AVERAT payload location
spoofed_processes:
- ora_ppmond # Oracle telecom HSS/OSS/BSS
- snipe-smtpd, earsd, rblsmtpd # Sniper/SpamSniper platform
- chronyd, rsyslogd, crond, polkitd, NetworkManager, tuned, watchdogd
crypto_constants:
averat_mac_key: 5d 0c f9 47 e4 ea 7b 18 1b ed 5e b1 fb 5c 56 3f
averat_aux_key: 6b 6a 48 0e f8 ae 5f 1b 38 e6 c0 94 86 df e3 45
averat_beacon_tag: 00 80 04 00
averat_protocol_magic: 1571 / 0x0623
dropper_aes_key: 6C CA D5 17 0E 3D B8 17 B3 DF 52 E0 D9 71 B1 48 # first 16 bytes of SHA1("ShareTech")
rekoobe_xor_key: 'uvTIgh47,@#R'
bpfdoor_sk_magic: 0x6693 (UDP), 0x4274 (TCP), 0x7820 (ICMP)
note: >
All network indicators defanged. Hashes and crypto constants are reported as
disclosed in Rapid7's indicators-of-compromise tables. The three IPv4 C2
addresses are compromised third-party relay devices, not operator-owned
infrastructure. Rapid7 states additional YARA rules and IOCs are available in
its Intelligence Hub.Legal and Regulatory Response
No law-enforcement action, takedown, sanction, or incident-specific government advisory tied to this AVERAT/BPFDoor campaign had been published as of October 6, 2026; Rapid7's report is a vendor research disclosure and announces none.1 Rapid7 references the pre-existing CISA/NCSC-UK joint advisory AA26-113A (April 2026) on China-nexus covert/ORB networks only as a device-class pattern its infrastructure resembles, not as a response to this campaign.1 No CERT-level advisory from South Korea's KrCERT/KISA or Taiwan's TWCERT specific to these samples was identified in the reporting reviewed as of that date.136
Impact Assessment
- Confirmed: Three third-party devices — a Synology NAS, a NetKlass SMB appliance, and a Dahua DVR in Chunghwa Telecom HiNet (AS3462) — are compromised and repurposed as operational relays with operator-installed PPTP.1
- Confirmed: Twelve distinct malware samples (dropper, six AVERAT builds, two SpamSniper BPFDoor sniffers, two data-plane BPFDoor samples, one BPF Rekoobe) were analyzed, each with a unique SHA-256.1
- Reported, not independently confirmed: The campaign targets telecom and network-edge/mail-security operators in South Korea and Taiwan, inferred from the mimicked products (SpamSniper, ShareTech) and appliance classes.13
- Estimated: SpamSniper's installed base — more than 6,000 organizations as of July 2023 per the Japanese B2B platform IPROS, cited by Dark Reading — indicates the exposed population, not confirmed victims.2
- Unknown: The number of compromised customer organizations, the identities of any targeted telecoms, dwell time, and whether data was exfiltrated. Rapid7 discloses no victim count.16
Lessons and Defensive Recommendations
For SOC/defenders:
- Hunt on Linux edge appliances for processes whose executable has been unlinked —
/proc/<pid>/exeending in(deleted)— and for executable memory maps with no backing file, the signature of this fileless chain.1 - Alert on the dropper artifacts: the directory
/HDD/ms6x2xTo64/, a#!/bin/shscript carrying a.phpextension, and anexecProcEndmarker; and on the process-tree sequence ofsh -con a.phppath followed bycp/chmodinto/sbinand anrm -rfwithin ~10 seconds.1 - Treat outbound TCP/25 from any process that is not a mail service as suspicious — especially from a process renamed to a common daemon — and investigate outbound SMTP from an appliance to mail-role hostnames that resolve to consumer-grade or embedded devices.1
- Investigate unexpected raw packet sockets and classic BPF filters on hosts that do not require packet capture.1
For platform / network-edge teams:
- Baseline normal outbound mail traffic from each appliance; without it, SMTP-cloaked C2 floats alongside legitimate mail flow and network detection must fingerprint the implant's fixed TLS handshake rather than watch a port, which the implant can change at runtime.2
- Restrict management access to routers, DVRs, NAS units and other edge appliances, and monitor NFS/SMB mounts that could let an adjacent host write executables onto an embedded device.1
For leadership:
- Vendor-managed mail-security appliances and SEGs cannot run EDR, sit in a trusted edge position, and are rarely monitored closely — a combination that makes them a durable espionage foothold. Fold them into asset inventory, patching and monitoring programs rather than treating them as closed boxes.2
- Retire end-of-life internet-facing NAS and DVR equipment; such devices are precisely the unpatched, unmonitored class recruited into ORB relay networks.1
Sources
Footnotes
-
Rapid7 — SMTP is the key: BPFDoor and AVERAT hitting the network edge — October 2, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26 ↩27 ↩28 ↩29 ↩30 ↩31 ↩32 ↩33 ↩34 ↩35 ↩36 ↩37 ↩38 ↩39 ↩40 ↩41 ↩42 ↩43 ↩44 ↩45 ↩46 ↩47 ↩48 ↩49 ↩50
-
Dark Reading — Malicious Linux Implants Mimic Asian Mail Security Products — October 2, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8
-
Infosecurity Magazine — Linux Backdoors Target Telecoms, Masquerade as Email Traffic — October 5, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6
-
SC Media — BPFdoor hides deep inside the OS kernel to target telecoms worldwide — March 26, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7
-
Cybersecurity Dive — Espionage campaign targets telecom with stealthy Linux-based backdoor — March 27, 2026 ↩ ↩2 ↩3 ↩4
-
securityonline.info — BPFDoor and AVERAT: SMTP-Cloaked Linux Backdoors Hit Telecom Edge — October 5, 2026 ↩ ↩2 ↩3 ↩4 ↩5
Related Research
Rapid7 found 'ted', a backdoor a DPRK-linked APT compiled into victims' HAProxy load balancers as a native plugin — reading their decrypted traffic and routing C2 through the load balancer itself. A companion CurlRAT toolkit hid in five trojanized Linux daemons; targets were South Korean firms.
Russia's FSB-linked Star Blizzard used a new delivery technique, RedFlick, in 13 phishing campaigns affecting 100+ US and UK organizations to deploy its CosmicPulse backdoor in 2026.
China-nexus actor UAT-11587 hit ~350 endpoints across 8 countries with Antino, a Rust backdoor that uses Outlook and OneDrive via Microsoft Graph for stealth C2, per Cisco Talos.