Rapid7 Finds Linux Backdoors Hiding in Mail Traffic
Rapid7 said on October 2 that it observed BPFDoor, BPF Rekoobe, and AVERAT against telecom and network-edge Linux appliances in South Korea and Taiwan. The implants make their network traffic look like ordinary mail by connecting on TCP port 25, speaking SMTP, and then switching to encrypted sessions after EHLO and STARTTLS.
The trick is not just the protocol but the disguise: some builds also spoof process names from legitimate services, so flow records and daemon checks can look normal while the box is running covert shells, file transfers, proxying, or port-forwarding channels. On a mail-capable appliance, that makes hostile traffic blend into the device's expected job.
If your monitoring leans on port-25 allowlists or flow-only views, these appliances sit in a blind spot where encrypted command-and-control can masquerade as routine mail setup. The exposure lasts as long as the platform is trusted to speak SMTP and the operator trusts the process name or session shape at face value.