ThreatPaper
Assessed, Not Confirmed

New BPFDoor variants let 'Chinese handlers' keep spying on telecoms

Assessment

Dark Reading's October 2, 2026 coverage of the Rapid7 report states that each time BPFDoor is documented it adapts, 'this allows its Chinese handlers to continue spying on global telecommunications companies' — asserting a Chinese state link for this SMTP/AVERAT campaign as settled fact. The primary research does not support that confidence: Rapid7 explicitly declined to name an actor for this campaign, assessed only that the relay device-class profile matches the China-nexus covert/ORB pattern in CISA/NCSC-UK advisory AA26-113A, found no overlap with any named ORB network (LapDogs/UAT-7810, SPACEHOP, FLORAHOX), and said 'specific attribution should remain an ongoing assessment.' A China-nexus link is a real infrastructure-level assessment, but treating named 'Chinese handlers' of this campaign as established is over-confident.

Where this claim appeared

Dark Reading · 2026-10-02

https://www.darkreading.com/threat-intelligence/malicious-linux-implants-mimic-asian-mail-security

What “Assessed, Not Confirmed” means

A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.

4 of 5 · rating scale

Assessed in

AVERAT and BPFDoor: SMTP-cloaked Linux implants mimic South Korean and Taiwanese mail-security appliances

Think this assessment is wrong? Report an error.