Yaamlabs
Threat intel

Linux backdoors pose as mail security tools in Korea, Taiwan

BPFDoor, a port 25 Rekoobe build and the new AVERAT implant hide on telecom and mail appliances as SpamSniper and ShareTech. How they work and how to hunt.

By Yaali. October 7, 2026, 6 min read, Threat intel, Resilience.

Cover illustration of an email security appliance in a dark server room with a glowing tendril reaching into its ports, with the Yaamlabs logo and the text: Linux backdoors hide inside mail security appliances, TCP 25, the port every implant uses

Rapid7 published research on October 2 describing Linux backdoors planted on telecom and network edge appliances in South Korea and Taiwan. In South Korea, a new BPFDoor variant and a BPFDoor-style build of the Rekoobe backdoor pretend to be parts of SpamSniper, a Korean anti-spam product. In Taiwan, a previously unreported implant Rapid7 calls AVERAT runs on ShareTech appliances, a Taichung vendor of firewalls, mail servers and spam filtering gateways.

All three families use TCP port 25, the port for SMTP mail, as their channel. A mail gateway talking SMTP looks normal in flow records, so the trick defeats the network check most teams rely on. If you run SpamSniper, ShareTech or any Linux-based mail or edge appliance, or you operate telecom infrastructure in the region, the hunting steps below apply to you.

Three implants and how each hides: BPFDoor and BPF Rekoobe in South Korea masquerading as SpamSniper and Oracle telecom processes and waiting for a magic packet, and AVERAT in Taiwan calling out over SMTP with STARTTLS to relays on compromised Taiwanese devices

How it works

BPFDoor is a passive backdoor. It opens no listening port. Instead it opens a raw packet socket and attaches a classic Berkeley Packet Filter (BPF), the same kernel feature tcpdump uses, so it sees every packet reaching the host before the firewall does. It stays silent until a packet carries the right "magic" bytes and a password, then it opens a reverse or bind shell. The South Korean variant checks for magic values on UDP, TCP and ICMP, and another variant hides the trigger inside ordinary HTTPS POST requests, relying on the SSL offloading common in telecom networks to deliver the decrypted packet to the infected node.

The disguise is specific to the victim. The Korean samples use /var/run/spamsniper.pid as their lock file and rotate through ten process names, from /usr/sbin/chronyd and /usr/sbin/rsyslogd -n to kernel thread lookalikes such as [watchdogd] and [kaluad_sync]. Others take names from the SpamSniper install tree (/sniper/snipe/bin/snipe-smtpd, /sniper/bin/earsd --start) or ora_ppmond, which mimics the naming of Oracle-backed subscriber and provisioning platforms such as the Home Subscriber Server (HSS).

The Rekoobe build applies the same idea to mail traffic. Its 26-instruction BPF filter only passes TCP, UDP and SCTP packets whose source and destination ports are both 25, then waits for a 32-byte magic sequence. Rapid7 notes that firewall rules on these appliances already accept such traffic as mail relay, so the trigger arrives without any rule change.

AVERAT works the other way round: it calls out. Every 600 to 699 seconds it connects to its controller on TCP 25, sends a real EHLO and asks for STARTTLS, then runs its own hand-built TLS session and an AES-CBC channel authenticated with HMAC-SHA1. Its command set covers file listing, upload and download, process listing and killing, up to ten concurrent shells, loading shared libraries, port forwarding, changing the controller address at runtime and rebooting the device. Rapid7 found six builds.

On ShareTech devices a dropper installs it. The dropper's strings are encrypted with AES-128 using the first 16 bytes of the SHA-1 hash of the word "ShareTech". It only runs if /tmp/flag exists, then writes a shell script with a .php extension to /HDD/ms6x2xTo64/updIptable.php. The script copies /addpkg/sbin/update to /sbin/ntpdate and /addpkg/sbin/agetty to /sbin/udevds, starts each one and deletes the file ten seconds later. The implants then run only from memory, and /proc/<pid>/exe shows the path with (deleted) after it.

What attackers are doing

Rapid7 says the dropper is a local installer run after access was already gained, and does not say how the attackers got in. Three AVERAT builds report to hardcoded IP addresses on Chunghwa Telecom's HiNet network that belong to compromised Taiwanese devices: a Synology NAS, a NetKlass small business router and a Dahua DVR. All three had the same operator-installed PPTP VPN service on port 1723. The other builds use attacker-registered domains dressed up as mail hosts.

Rapid7 does not name an actor in this report. It says the relay pattern matches the operational relay box (ORB) networks of compromised routers, NAS units and cameras described in the April 2026 CISA and NCSC-UK advisory on China-nexus actors. The Hacker News links the activity to Red Menshen (also tracked as Earth Bluecrow), the group Rapid7 tied to BPFDoor inside telecom networks in its March 2026 research. Treat that link as likely rather than confirmed.

What to do

Hunting and response checklist: block the listed indicators, find raw packet sockets, flag port 25 traffic from non-mail processes, check for deleted executables and the ShareTech staging paths, then rebuild and rotate

No CVE is involved, so there is nothing to patch. The work is hunting and containment.

1. Block the known infrastructure

Add these to your firewall, DNS and proxy deny lists and search past logs for them: the domains mx.zxopfds.com, spam.suwaccqi.com and mx1.wwstifsteel.com, and the relay addresses 59.125.211.65, 122.116.138.33 and 1.34.200.85. The Rapid7 report lists SHA-256 hashes for the dropper, all six AVERAT builds and five BPFDoor and Rekoobe samples.

2. Find raw packet sockets

On a mail gateway or appliance that does no packet capture, any process holding a packet socket is suspect. Run ss -0pb as root to list packet sockets with the owning process and attached BPF filter, or check /proc/net/packet and match the inode to a PID. Then confirm the process is what its name claims: ls -l /proc/<pid>/exe should point at the real binary, and cat /proc/<pid>/cmdline should match how the package normally starts it.

3. Check every connection on port 25

On mail appliances, list port 25 connections with ss -tnp '( sport = :25 or dport = :25 )' and confirm each belongs to the actual mail service (Postfix, Sendmail or the vendor daemon). Outbound SMTP from an appliance to a consumer broadband address, a NAS or a DVR deserves a closer look, as does a session to a host whose MX-style name does not match any partner you exchange mail with.

4. Look for the file traces

  • Running processes whose executable shows (deleted): ls -l /proc/*/exe 2>/dev/null | grep deleted.
  • /var/run/spamsniper.pid on a host where SpamSniper does not create it, or a second copy beside the real one.
  • On ShareTech devices: /tmp/flag, anything under /HDD/ms6x2xTo64/, a file named execProcEnd, and the AVERAT state files /var/lib/.db, /var/lib/.sencha, /var/lib/.us and /var/lib/.a.
  • Shell history or process logs showing cp into /sbin followed by rm -rf of the same file within about ten seconds.

5. If you find a hit

Capture memory and the process before rebooting; with fileless implants a reboot destroys the evidence. Then rebuild the appliance from vendor firmware rather than cleaning it, rotate the admin, SSH and API credentials it held, and review any mail relay or TLS keys stored on it. Ask the vendor whether other customers have reported the same paths. Check your own estate for Synology, NetKlass or Dahua devices with PPTP exposed on 1723, in case your devices are someone else's relay.

Appliances need the same telemetry as servers

These implants work because mail and edge appliances are closed boxes that rarely run endpoint detection, and because port 25 traffic from a mail gateway is assumed to be mail. If you cannot install an agent, collect what you can: process and socket listings on a schedule, NetFlow with process context where the vendor allows it, and alerts on SMTP sessions to address ranges you never send mail to.

Our network penetration testing covers mail gateways and edge appliances as targets, and our security operations work builds the socket and port 25 checks above into routine monitoring. Open the chat and Yaali, our AI agent, will pass your question to an engineer.


Sources: Rapid7 research, The Hacker News, Infosecurity Magazine, SC World on Rapid7's March BPFDoor research, ShareTech at CYBERSEC.

Read next

Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.