Malware · 10h ago

Rapid7 Finds Linux Backdoors Wearing Appliance Clothes

Rapid7 says three Linux backdoors are impersonating Korean and Taiwanese email-security appliances by copying filenames, allowed traffic, and normal background behavior, making the implants hard to spot inside edge networks. The activity spans adjacent campaigns built around BPFdoor, Rekoobe, and a new tool Rapid7 calls AVERAT.

The trick is not just a fake name. The malware follows the appliance’s outward habits closely enough that perimeter tools may treat it like trusted edge gear instead of an intruder, so allowlists and special trust exceptions can hide the compromise rather than reveal it.

For teams that rely on appliance traffic as a signal of legitimacy, the detection problem shifts onto the host: what matters is whether the box is really running the software it claims to be, not whether its packets look familiar.

Timeline

Sources

2 sources covering this story

Part of the PlainSec briefing for 2026-10-02

Editions

Related stories