Malware · 10h ago
Rapid7 says three Linux backdoors are impersonating Korean and Taiwanese email-security appliances by copying filenames, allowed traffic, and normal background behavior, making the implants hard to spot inside edge networks. The activity spans adjacent campaigns built around BPFdoor, Rekoobe, and a new tool Rapid7 calls AVERAT.
The trick is not just a fake name. The malware follows the appliance’s outward habits closely enough that perimeter tools may treat it like trusted edge gear instead of an intruder, so allowlists and special trust exceptions can hide the compromise rather than reveal it.
For teams that rely on appliance traffic as a signal of legitimacy, the detection problem shifts onto the host: what matters is whether the box is really running the software it claims to be, not whether its packets look familiar.
2 sources covering this story
Malicious Linux Implants Mimic Asian Mail Security Products
A trio of newly discovered backdoors walk and quack like legitimate edge solutions, so it's hard to tell they're not.
SMTP is the key: BPFDoor and AVERAT hitting the network edge
The set spans a newly observed BPFDoor variant, a BPF Rekoobe build seen against South Korean targets, a dropper, and six builds of a Linux implant deployed against Taiwanese appliances.
Part of the PlainSec briefing for 2026-10-02