$ techbeacon▋
Malware

Rapid7 Detects New Linux Backdoors Hiding in Email Traffic Targeting Korean and Taiwanese Telecom Gear

Rapid7 Detects New Linux Backdoors Hiding in Email Traffic Targeting Korean and Taiwanese Telecom Gear

Security firm Rapid7 has identified a trio of previously unseen Linux-based backdoor families—BPFDoor, BPF Rekoobe and AVERAT—that are specifically targeting telecommunications and network‑edge devices in South Korea and Taiwan. The malware variants exploit the Berkeley Packet Filter (BPF) subsystem to embed malicious code while disguising their network communications as routine email traffic.

The discovery follows a broader trend of threat actors focusing on the critical infrastructure that underpins regional communications networks. Telecom equipment often runs hardened Linux distributions, making it an attractive target for attackers seeking persistent, low‑profile access. By leveraging BPF, the new malware can operate at the kernel level, evading many conventional detection tools that monitor only user‑space processes.

Rapid7’s analysis indicates that the three families share a common technique: they intercept outbound SMTP packets, embed encrypted command‑and‑control (C2) instructions within the payload, and then forward the traffic to legitimate mail servers. This “email masquerading” approach blends malicious traffic with normal business communications, reducing the likelihood of raising alerts on network monitoring systems.

Initial indicators suggest that the campaigns have been active for several months, with compromised devices found in data centers and edge routers that serve mobile operators and internet service providers. While the exact attribution remains unclear, the focus on South Korean and Taiwanese infrastructure aligns with heightened geopolitical tensions in the region and a history of cyber‑espionage targeting critical sectors.

Industry experts warn that the stealthy nature of BPF‑based exploits could complicate remediation efforts. Traditional antivirus signatures may miss the kernel‑level hooks, and the encrypted C2 channel hidden within email traffic can bypass standard intrusion‑detection signatures. Rapid7 recommends that operators implement strict egress filtering for SMTP, apply the latest kernel patches, and employ BPF monitoring tools that can detect anomalous filter programs.

Telecom providers in the affected countries are reportedly working with national CERT teams to assess the scope of infection and to roll out security updates. The emergence of these backdoors underscores the ongoing challenge of protecting the software supply chain and the need for continuous threat‑intelligence sharing among vendors, operators, and security researchers.

Mahesh Kumar Sahoo — Mahesh covers ransomware gangs, data leak sites, and dark web marketplaces, mapping how stolen data surfaces and gets sold. Follows ShinyHunters-style groups across leak forums.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related