Two reported Linux malware campaigns aimed at telecom, mail-security and network-edge environments in South Korea and Taiwan disguise themselves as legitimate software and make command traffic resemble email activity. A secondary summary of Rapid7’s October 2, 2026 report describes BPFDoor and a modified Rekoobe posing as South Korean SpamSniper software, and AVERAT builds impersonating Taiwanese ShareTech mail-security appliances. The summary says their SMTP-like communications use TCP port 25; it does not establish that every implant shares the same behavior or how attackers first gained access.
What the reported campaigns have in common—and how they differ
The activity is described as two campaigns, not one uniform backdoor. Both use software impersonation and email-like network traffic to make malicious activity harder to distinguish from ordinary appliance or mail-system operations. Their targets, disguises and reported implant behaviors differ.
| Reported activity | Target environment and disguise | Reported implant and communications behavior |
|---|---|---|
| South Korea-focused | Telecom and mail-security environments; implants reportedly imitate SpamSniper-related process names, paths and PID-file conventions. | Two BPFDoor variants and a modified Rekoobe are described. BPFDoor variants reportedly wait for a packet trigger; one analyzed variant is also described as supporting HTTP tunneling over an HTTPS POST. |
| Taiwan-focused | Mail-security and network-edge environments, including embedded appliances, NAS devices and CCTV/DVR equipment; builds reportedly impersonate ShareTech mail-security appliances. | AVERAT, described as a modular remote-access trojan, reportedly uses a channel resembling SMTP/STARTTLS over TCP port 25. Its described command set includes file operations, process control, interactive shells, module loading, reboot and port forwarding. |
These are claims in Threadlinqs Intelligence’s October 3, 2026 secondary summary of Rapid7’s report, not independent verification of the underlying binaries. The table distinguishes behaviors attributed to particular analyzed samples; it should not be read as a checklist of features present in every BPFDoor, Rekoobe or AVERAT infection.
How the disguises and email-like traffic work
Familiar-looking files and processes
The summary says the implants imitate filenames, process names and PID-file conventions associated with legitimate mail-security software. A daemon-like process name can therefore appear routine even when the executable is running from an unexpected directory. A process may also keep running after its executable has been deleted from disk, making its resolved path an important part of an investigation.
#1 Best Overall
Reported paths and filenames include /var/run/spamsniper.pid, /HDD/ms6x2xTo64/, /addpkg/sbin/update, /addpkg/sbin/agetty and /var/lib/.db. Treat these as leads, not a complete or definitive indicator list: filenames can change, legitimate software may use similar names, and the summary advises validating indicators against current vendor reporting.
SMTP-like command traffic
The reported AVERAT channel is described as resembling SMTP/STARTTLS over TCP port 25. The broader finding is that command traffic can blend into a protocol commonly associated with mail delivery. That does not mean the traffic is ordinary email, nor does it show that all the reported implants communicate in precisely the same way. The South Korea-focused BPFDoor and modified Rekoobe activity should be assessed separately from the Taiwan-focused AVERAT activity.
Rank #2
Packet-trigger behavior is specific to the reported BPFDoor variants
The summary describes the BPFDoor variants as dormant until they receive a packet trigger. It also describes one variant as supporting HTTP tunneling over an HTTPS POST. These sample-specific details do not establish that all versions of BPFDoor behave this way, and they are not described as AVERAT features.
What defenders can check
Prioritize mismatches between a process’s apparent identity, its executable location and its network activity. The indicators below are investigative leads from the secondary summary, not a complete incident-response procedure.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware match- Review unexpected daemon-named processes. Check whether the executable is running from a path that fits the installed software and whether the process resolves to a deleted file. A familiar process name alone does not establish legitimacy.
- Investigate raw packet sockets. Look for unexpected
PF_PACKETraw sockets with classic BPF filters, particularly on hosts that are not intended to perform packet capture or network monitoring. - Alert on unusual outbound SMTP. Identify processes and systems initiating outbound TCP port 25 connections when they are not expected to deliver mail. Restrict SMTP egress so that only approved mail relays can connect externally.
- Search for the reported paths and names. Include
/var/run/spamsniper.pid,/HDD/ms6x2xTo64/,/addpkg/sbin/update,/addpkg/sbin/agettyand/var/lib/.dbin a targeted review, then validate any matches against current vendor indicators and the host’s expected software. - Review appliance exposure. Segment mail-security appliances, limit access to their management planes, and retire or isolate exposed end-of-life edge equipment. Investigate unexpected PPTP listeners as a separate suspicious finding.
If a check raises concern, preserve relevant logs and evidence and follow your organization’s incident-response process. A path match, open port or suspicious process is a reason to investigate, not by itself proof of compromise.
What is—and is not—established about access and attribution
The available technical summary identifies no CVE or initial-access vulnerability. That means the described material does not establish how the operators entered the affected environments; it is not evidence that a particular vulnerability was or was not used.
Rank #4
The summary says Rapid7 assessed the use of compromised edge devices as relays as consistent with China-nexus operational relay box (ORB) networks discussed in a joint advisory. It characterizes the China-nexus connection as low confidence and does not confirm that the activity belongs to any named ORB network. Infrastructure resemblance should not be presented as confirmed attribution to a country, group or network.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Source and confidence limits
The technical detail here comes from Threadlinqs Intelligence’s October 3, 2026 secondary summary of Rapid7’s October 2 report. The summary says the underlying Rapid7 page could not be opened, so its sample-level behavior and indicators have not been independently checked here against that primary report. Infosecurity Magazine’s search-result excerpt independently describes the broad finding—Linux backdoors targeting telecom and network-edge appliances in South Korea and Taiwan while using email-like traffic and legitimate-looking processes—but its article page was unavailable. No attributable quotation or population-level statistic is established by those materials.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

