New Linux Backdoors Target Telecom Appliances in South Korea and Taiwan
Cybersecurity researchers have detected new variants of Linux backdoors disguising network traffic as legitimate email communication to compromise telecom infrastructure in East Asia.
FTMQ Security, written by our newsroom0 views

InfoSecurity Magazine reported that security firm Rapid7 uncovered new Linux malware variants targeting telecommunications and network-edge appliances in South Korea and Taiwan. The research published on October 2 details newly observed builds of BPFDoor, BPF Rekoobe, and an implant named AVERAT. [1]
According to InfoSecurity Magazine, the newly identified backdoors hide their presence on compromised devices by disguising network traffic as legitimate email and spoofing process names. The AVERAT implant establishes outbound connections over Transmission Control Protocol port 25 and utilizes Simple Mail Transfer Protocol commands, sending an EHLO request and initiating STARTTLS before executing its encrypted payload. [1]
Rapid7 observed the BPFDoor variant and BPF Rekoobe build deployed against targets in South Korea, as reported by InfoSecurity Magazine. In Taiwan, attackers deployed a dropper alongside six distinct builds of the AVERAT implant against network-edge hardware. [1]
Linux operating systems are generally regarded as well protected against computer viruses, though they remain vulnerable to specialized malware, as noted in general background documentation. Email filtering systems typically process automatic SMTP server messages to screen incoming and outgoing traffic. [2][3]
In short
- Rapid7 uncovered new BPFDoor, BPF Rekoobe, and AVERAT Linux malware variants on October 2.
- The backdoors target telecom and network-edge appliances in South Korea and Taiwan.
- AVERAT connects over TCP port 25 using SMTP commands and STARTTLS encryption to conceal traffic.
Sources
Every paragraph above points to the numbered items it rests on. Read the originals here.
- [1]New Stealthy Linux Backdoors Target Telecoms, Masquerade as Email TrafficInfoSecurity Magazine, 1d ago (the report this story comes from)
Background
- [2]Linux malware on Wikipedia
- [3]Email filtering on Wikipedia
- [4]Telecommunications on Wikipedia
Our newsroom writes these reports with the help of software, from the 4 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.
More in Data Breaches
Get the day in one email
Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments
Loading
Join the conversation
Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.
Already on the list? Enter the same address and we will send a sign-in link.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.