Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

New Linux malware reported by Rapid7 on October 2, 2026, tries to blend into the specific edge appliances it compromises. The samples imitate local process names and file conventions, remove some staged files after launch, and—in the BPF implants—wait for matching network traffic rather than simply exposing an obvious listening port. That makes a file-only or open-port-only check inadequate; defenders should correlate process state, packet-filter activity, and network behavior.

What did Rapid7 find?

Rapid7’s October 2, 2026 report describes several distinct Linux samples: a newly observed BPFDoor variant, a BPF Rekoobe build observed against South Korean targets, a dropper, and six AVERAT builds deployed against Taiwanese appliances. The report points to telecom and network-edge operators as the most affected contexts, including embedded CCTV and DVR devices near the network core. These observations do not establish that every Linux router, mail gateway, or appliance vendor is affected.

Sample or component Reported context or behavior Why the distinction matters
BPFDoor Rapid7 reports a newly observed variant that impersonated a SpamSniper PID file and rotated among common Linux daemon names. The names and artifacts are meant to resemble local software, not to identify the process as legitimate.
BPF Rekoobe A build was observed against South Korean targets. Rapid7 says it used process names associated with Sniper appliance software as well as generic Linux daemons. This is a reported appliance-specific naming tactic in a particular target context, not a claim about every Rekoobe sample.
Dropper Rapid7 describes a dropper apparently built for ShareTech appliances. Its encrypted material uses a key derived from “ShareTech,” and it writes into an appliance add-on package directory. The reported vendor-specific clues help explain how deployment can be tailored to a device environment.
AVERAT Rapid7 reports six builds deployed against Taiwanese appliances. Six is a build count, not a confirmed count of victims or infections.

Rapid7 presents these components together in a network-edge investigation; that does not prove a single actor is responsible for every component. Nor does the report confirm that the samples belong to a named operational relay network.

How does the malware imitate an edge appliance?

It borrows expected names and locations

Appliances often run a narrow set of vendor-specific services alongside familiar Linux processes. According to Rapid7, some samples used names and PID-file conventions associated with SpamSniper or Sniper appliance software, while others used ordinary daemon names. The ShareTech-oriented dropper’s add-on-package path is another example of deployment tailored to local conventions. A process name that looks normal in a listing therefore is not proof that the executable is genuine.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

It can leave less behind on disk

Rapid7 describes a staging sequence in which a script with a misleading extension copies payloads into /sbin under ordinary-looking names, launches them, and deletes the files shortly afterward. A process can continue running after its original executable file has been unlinked, so a later search for suspicious files may miss the image that started it. The report recommends examining process executable links and memory maps as well as the staging sequence and process ancestry.

Why can a backdoor be hard to spot on the network?

The BPF implants described by Rapid7 wait passively for matching traffic instead of simply opening an obvious listening port. That means the absence of a conspicuous listening service does not establish that an appliance has no backdoor. The report highlights SMTP traffic, including port 25, as a plausible camouflage channel on mail-security devices.

Rapid7 also says the implants use a fixed TLS ClientHello template that may be a more durable fingerprint than the destination port, which can be changed at runtime. It advises looking for unexpected outbound SMTP from an appliance to hostnames resolving to consumer-grade or embedded devices. Protocol tunneling is a general technique documented in MITRE ATT&CK’s T1572 reference, but that general reference does not establish that every sample in Rapid7’s report uses tunneling.

What should defenders check?

Rapid7’s indicators are investigation leads, not proof of compromise on their own. Where appliance access permits, correlate host and network evidence rather than relying on a single alert or scan.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Inspect process and execution state

  • Review /proc/<pid>/exe for processes whose executable link points to an unlinked path.
  • Look for executable memory pages without backing files in process memory maps.
  • Preserve process names, arguments, ancestry, and open file descriptors. Compare an ordinary-looking name with the executable path, runtime state, and the appliance’s expected software.
  • Reconstruct sequences in which a shell script copies a payload into /sbin, launches it, and then removes the file.

Check packet-filter and socket activity

  • Investigate unexpected raw packet sockets and classic BPF filters, especially on devices that have no operational need for packet capture.
  • Do not treat the lack of an open listening port as an all-clear; investigate whether a process is waiting for matching traffic.

Correlate mail and other network traffic

  • Review port-25 callbacks from processes that are not mail services, and investigate outbound SMTP from appliances to hostnames resolving to consumer-grade or embedded devices.
  • Where network visibility allows, compare TLS ClientHello behavior with the fixed template described by Rapid7; the report cautions that a port alone may be less durable because it can change at runtime.
  • Preserve socket metadata and relevant historical DNS records so the investigation can connect a process to its past destinations.

Look beyond the appliance itself

  • Restrict management access to edge devices and check whether shared NFS or SMB mounts could provide a route for writing executables to embedded systems.
  • Preserve process trees, arguments, descriptors, socket metadata, and relevant DNS history during incident response. These details can disappear or be harder to reconstruct after the process exits or state changes.
  • Account for deployment limits: Rapid7 notes that closed, vendor-managed appliances may not support EDR or other endpoint agents. If agents cannot run, use available host inspection and network telemetry rather than assuming standard endpoint coverage.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is known—and not known—about the scope?

The report’s observations are geographically and technically bounded: it describes South Korean and Taiwanese appliance contexts and broader relevance to telecom and network-edge operators. It does not provide a population prevalence or infection-rate statistic, so the sample count cannot be used to estimate how widespread compromise is. Rapid7 also says the infrastructure resembles a broader device-class pattern but reports no overlap confirming membership in specified relay networks; attribution to a named group or operation would go beyond the evidence presented.

For further technical indicators and YARA rules, Rapid7 identifies its Intelligence Hub as a source of additional threat intelligence. Christiaan Beek, Rapid7’s vice president of Intelligence, told Dark Reading that edge devices sit between the Internet and core networks and may be trusted by firewall rules, making a foothold useful for persistent access in telecom environments. Beek also noted that closed, vendor-managed boxes may not support EDR and may receive little monitoring. These points explain the defensive concern; they do not show that every appliance is vulnerable or compromised.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.