Executive Summary
Rapid7 has identified a sophisticated set of Linux-based samples targeting telecommunications and network-edge infrastructure in South Korea and Taiwan. The campaign utilizes regionalized disguises, including process spoofing of local anti-spam products like SpamSniper and ShareTech appliance conventions. The primary threats identified are modular variants of BPFDoor, a Rekoobe-based backdoor, and a newly discovered implant named AVERAT.
The attackers leverage stealthy persistence mechanisms, such as staging payloads in memory and immediately deleting on-disk images, alongside network tradecraft that encapsulates malicious traffic within legitimate-looking SMTP (port 25) and HTTPS POST requests. The infrastructure supporting these operations consists of compromised consumer-grade and SMB appliances (NAS, DVRs, routers) repurposed as Operational Relay Boxes (ORBs), aligning with China-nexus adversary patterns described in CISA advisory AA26-113A.
This activity poses a high risk to sectors relying on edge appliances, as the implants facilitate long-term persistence, proxying capabilities into internal LANs, and visibility into inbound/outbound organizational traffic while remaining invisible to traditional port scanning and simple network monitoring.
