New BPFDoor variants let 'Chinese handlers' keep spying on telecoms
Assessment
Dark Reading's October 2, 2026 coverage of the Rapid7 report states that each time BPFDoor is documented it adapts, 'this allows its Chinese handlers to continue spying on global telecommunications companies' — asserting a Chinese state link for this SMTP/AVERAT campaign as settled fact. The primary research does not support that confidence: Rapid7 explicitly declined to name an actor for this campaign, assessed only that the relay device-class profile matches the China-nexus covert/ORB pattern in CISA/NCSC-UK advisory AA26-113A, found no overlap with any named ORB network (LapDogs/UAT-7810, SPACEHOP, FLORAHOX), and said 'specific attribution should remain an ongoing assessment.' A China-nexus link is a real infrastructure-level assessment, but treating named 'Chinese handlers' of this campaign as established is over-confident.
Where this claim appeared
Dark Reading · 2026-10-02
https://www.darkreading.com/threat-intelligence/malicious-linux-implants-mimic-asian-mail-securityWhat “Assessed, Not Confirmed” means
A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.
4 of 5 · rating scale
Assessed in
AVERAT and BPFDoor: SMTP-cloaked Linux implants mimic South Korean and Taiwanese mail-security appliancesThink this assessment is wrong? Report an error.