BPFDoor and AVERAT Target Telecom Network Edge
Score: 9/10

BPFDoor and AVERAT Target Telecom Network Edge

Adversaries are deploying modular Linux implants including BPFDoor, Rekoobe, and the new AVERAT RAT against telecom edge appliances, utilizing SMTP-disguised C2 and BPF packet filtering to evade detection.

Executive Summary

Rapid7 has identified a sophisticated set of Linux-based samples targeting telecommunications and network-edge infrastructure in South Korea and Taiwan. The campaign utilizes regionalized disguises, including process spoofing of local anti-spam products like SpamSniper and ShareTech appliance conventions. The primary threats identified are modular variants of BPFDoor, a Rekoobe-based backdoor, and a newly discovered implant named AVERAT.

The attackers leverage stealthy persistence mechanisms, such as staging payloads in memory and immediately deleting on-disk images, alongside network tradecraft that encapsulates malicious traffic within legitimate-looking SMTP (port 25) and HTTPS POST requests. The infrastructure supporting these operations consists of compromised consumer-grade and SMB appliances (NAS, DVRs, routers) repurposed as Operational Relay Boxes (ORBs), aligning with China-nexus adversary patterns described in CISA advisory AA26-113A.

This activity poses a high risk to sectors relying on edge appliances, as the implants facilitate long-term persistence, proxying capabilities into internal LANs, and visibility into inbound/outbound organizational traffic while remaining invisible to traditional port scanning and simple network monitoring.

Key Details

Threat Name

AVERAT

Affects

Microsoft SharePoint

Adversary

UAT-7810 Other Adversaries and Aliases: SPACEHOP; FLORAHOX

Malware/Tools

BPFDoor, AVERAT, Rekoobe, Tiny Shell

Report Score

9out of 10
Quality Score
Excellent
IOC Quality10
TTP Details9
Detection Guidance7
Enterprise Relevance9
Clarity & Structure9
Technical Depth9

Sources