
Linux backdoors hide remote control in email traffic on appliance
Linux backdoors examined by Rapid7 mimic email security software and conceal remote-control traffic on telecom and network appliances in Korea and Taiwan.
Linux backdoors examined by Rapid7 are concealing remote-control activity behind email traffic and familiar software identities on telecom and network appliances in South Korea and Taiwan. The security company's analysis covers a new BPFDoor variant, a BPF Rekoobe build and a previously unreported implant called AVERAT. For businesses operating Linux infrastructure, the central finding is that a familiar process name or apparently routine mail connection is not sufficient evidence that activity is legitimate.
Malware commonly borrows the names of operating-system components to escape casual inspection. Rapid7 found a more locally tailored approach here: the samples imitate SpamSniper and ShareTech, email security products used in the targeted environments. Jiran Group markets SpamSniper as protection against spam, malware and server attacks. The observed impersonation does not establish a vulnerability in either vendor's software, and the supplied report does not identify the initial entry route or a patch for these infections.
The South Korean BPFDoor samples imitate SpamSniper's PID file, a file used to record a running program's process identifier, and cycle through ten Linux daemon names. Daemons are programs that work in the background. Another sample adopts a name resembling the naming convention used by a relational database server for its Process Monitor background component. That disguise fits telecom systems using that database server to support subscriber and provisioning platforms.
BPFDoor uses the Berkeley Packet Filter (BPF), a Linux facility for examining network packets, to watch incoming traffic for a specially formed activation message known as a magic packet. This passive approach can avoid conventional port scans, which look for services accepting connections. Rapid7 previously analysed BPFDoor extensively and linked its activity to Red Menshen, also known as Earth Bluecrow, DecisiveArchitect and Red Dev 18, with telecom targeting across the Middle East and Asia dating to 2021.
According to Rapid7, operators changed their delivery method after security vendors developed Suricata and Snort network-detection rules for transport-layer anomalies, irregularities in how network connections are carried. The activation packet can now travel inside an HTTPS POST request, a standard way of submitting data over an encrypted web connection. The method relies on SSL offloading, in which an intermediary removes the connection's encryption before forwarding traffic internally. Rapid7 says this can deliver the trigger through telecom edge proxies, intermediary systems at the network boundary, in a form that may evade deep packet inspection. That is a potential detection gap, not evidence that every inspection system is bypassed.
After activation, the BPFDoor sample starts TinyShell, a remote-control tool providing an interactive command session and file uploads and downloads. Rapid7 describes the samples as a modular framework incorporating TinyShell and Rekoobe logic to support data removal. A related Rekoobe-based BPF backdoor also names its processes after SpamSniper components. It intercepts IPv4 traffic using TCP, UDP or SCTP, different transport methods for network data, and IPv6 traffic using UDP, with both source and destination ports set to 25. IPv4 and IPv6 are the two main internet addressing systems; ports distinguish network services.
The Taiwanese activity introduces AVERAT, installed by a dropper, a program whose job is to place another malicious program on a device. Rapid7 found the dropper in ELF format, the executable format used on Linux, within the ShareTech appliance's "/addpkg/sbin/" add-on directory. It derives a decryption key from the string "ShareTech" and unlocks a shell script, a sequence of operating-system commands. That script stages and runs "ntpdate", the dropper itself, and "udevds", the AVERAT payload. Both files are deleted 10 seconds later.
AVERAT uses Simple Mail Transfer Protocol (SMTP), the protocol for sending email, for command-and-control (C2), communication through which an attacker directs malware. It contacts "mx.zxopfds[.]com" over TCP port 25 at intervals of 600 to 699 seconds. The server information and contact interval come from an encrypted configuration. This makes the Linux backdoor's external communication resemble activity that might be expected from an email appliance.
Its command set gives an operator extensive control. Codes 20 and 30 list directory contents and recursively traverse directory trees; 21 retrieves a file with support for resuming an interrupted transfer; 22 sends a file to the device in chunks; and 25 recursively deletes files or directory trees. Code 629 lists running processes and their command lines, while 632 requests process termination using SIGTERM, an operating-system termination signal. Code 842 replaces C2 host and port tables while the implant is running.
Further commands open up to 10 concurrent interactive shell sessions (912), send commands into an existing session (914), and reboot the appliance (916). Code 1010 loads or unloads a shared-object module, a .so file that adds executable functionality. Code 1576 changes the callback interval and saves it to a database, while 1618 opens a proxy or port-forwarding channel to relay connections through the appliance. Another command, whose code is unknown, closes the connection and immediately ends the process.
Rapid7 says AVERAT's control infrastructure resembles the device profile associated with an Operational Relay Box (ORB) network, a collection of devices used to relay traffic. However, it found no evidence connecting it to the known LapDogs (UAT-7810), SPACEHOP or FLORAHOX networks. That distinction matters: resemblance is not confirmed membership. The source also recalls persistent backdoors delivered through Barracuda Email Security Gateway vulnerabilities CVE-2023-2868 and CVE-2023-7102 in 2023, illustrating why email-filtering appliances warrant close security attention.
For administrators, the recommended checks are specific: investigate unexpected raw packet sockets, which let programs access network packets directly, and BPF filters on Linux systems that do not need packet capture. Audit outbound port 25 connections from programs that are not mail services, inspect processes masquerading as routine daemons, and restrict management access to routers, digital video recorders and other network-edge appliances. AEU-I's security-first IT, infrastructure and consulting services are relevant to businesses seeking help reviewing that infrastructure, without implying any involvement in Rapid7's findings. Website owners who delegate these systems should ask their provider to review the underlying processes and connections, rather than treating an apparently legitimate email-service name as reassurance.
How to Protect Yourself
- Send this report to your hosting or IT provider and ask whether they manage Linux or email-filtering appliances for your business.
- Ask your IT provider to check whether programs other than your email service are making outgoing email connections.
- Ask whoever manages your router and email appliance to restrict their administration pages to approved staff connections.
- Request a review of unfamiliar background programs, including ones using familiar email-security names, rather than stopping them yourself.
Vulnerabilities & Fixes
- CVE-2023-2868 A Barracuda Email Security Gateway vulnerability cited in the source as exploited in 2023 to deliver persistent backdoors; no fix details are supplied. View the fix & details →
- CVE-2023-7102 A Barracuda Email Security Gateway vulnerability cited in the source as exploited in 2023 to deliver persistent backdoors; no fix details are supplied. View the fix & details →
Terms Explained
- backdoor A hidden way to access or control a system without its owner's permission.
- Berkeley Packet Filter (BPF) A facility that lets software examine selected pieces of network traffic.
- dropper A malicious program that installs another malicious program.
- Simple Mail Transfer Protocol (SMTP) The set of communication rules used to send email between systems.
- command-and-control (C2) Communication that lets an attacker send instructions to malicious software.
- SSL offloading Removing a connection's encryption at an intermediary before passing its contents to another system.
- interactive shell A session in which someone can type commands and receive responses from a computer.