Threat reportMalwareTL-2026-2875
BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate SpamSniper and ShareTech Mail Security Appliances (SMTP/TCP 25 C2)
BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate (TL-2026-2875), also tracked as SMTP is the key campaign, is a high-severity malware campaign, first published 2026-10-03. It is linked to a China-nexus actor with low confidence, affects SpamSniper (South Korean anti-spam software) Linux mail security, maps to 16 MITRE ATT&CK techniques (T1027.013, T1036.004, T1036.005), and is covered by 9 detection rules and 27 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 16MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 27Indicators of compromise
Key facts for TL-2026-2875
- Threat ID
- TL-2026-2875
- Also known as
- SMTP is the key campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- telecoms, email security mail gateways, network edge appliances, cctv dvr
- Target regions
- south korea, taiwan
- Detection rules
- 9
- Indicators of compromise
- 27
Malware and tooling in BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate
Malware and tooling: AVERAT, BPFDoor, Rekoobe, tsh
How BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate works
Rapid7 documents two overlapping Linux implant campaigns that impersonate Asian email security appliances: new BPFDoor variants and a modified Rekoobe backdoor posing as South Korean anti-spam software SpamSniper, and a novel modular RAT, AVERAT, posing as Taiwanese ShareTech mail security appliances. Both abuse TCP port 25 for C2 and relay through compromised edge devices (Synology NAS, DVRs, SMB appliances). The BPFDoor cluster targets South Korean telecom/mail environments and is likely tied to Chinese-linked espionage.
Rapid7 (published 2026-10-02, 'SMTP is the key: BPFDoor and AVERAT hitting the network edge') analyzes a cluster of Linux malware that copies the filenames, PID files, process names and firewall-permitted traffic profile of email security appliances. Two overlapping campaigns are described.
Campaign 1 (South Korea): two new BPFDoor variants and one modified Rekoobe variant impersonate SpamSniper. The BPFDoor builds reuse the SpamSniper PID file (/var/run/spamsniper.pid) as a mutex and rotate through ten Linux daemon names (watchdogd, chronyd, polkitd, rsyslogd, crond, NetworkManager, python/tuned, scsi_tmf_6, charger_manager, kaluad_sync). They remain dormant until a magic value is observed in packets delivered through a raw packet socket with an attached classic BPF filter (variant magic values 0x6693 UDP, 0x4274 TCP, 0x7820 ICMP), with a new variant also supporting HTTP tunneling over HTTPS POST. The Rekoobe variant (652508a9...) installs a BPF filter on TCP/UDP/SCTP over IPv4 and UDP over IPv6 for port 25, spoofs SpamSniper process paths (/sniper/bin/crond, /sniper/bin/earsd, /sniper/apache/bin/httpd, /sniper/snipe/bin/snipe-smtpd, /sniper/autorun/rblsmtpd) and suppresses shell history (VIMINIT, HISTFILE=/dev/null, HISTSIZE=0, HISTFILESIZE=0). Data-plane variants spoof ora_ppmond, /sniper/snipe/bin/dtnpd and /sniper/bin/ofgmd and embed Tiny Shell.
Campaign 2 (Taiwan): AVERAT, a novel modular RAT, ships in six builds against embedded appliances, Synology NAS and CCTV/DVR devices, delivered by a ShareTech-themed dropper whose payload is AES-128-ECB encrypted with a key derived from SHA1('ShareTech'). The dropper is gated by /tmp/flag, runs /HDD/ms6x2xTo64/updIptable.php, copies two binaries into /sbin under alternate names (ntpdate, udevds), launches them and unlinks each about ten seconds later while processes keep running; payloads land at /addpkg/sbin/update and /addpkg/sbin/agetty. AVERAT beacons every 600-699 seconds over a SMTP/STARTTLS-looking channel on TCP/25, reporting hostname, user, OS version, interfaces and logged-in users, and persists 276-byte encrypted state in /var/lib/.db (or .sencha, .us, .a). Its command set includes directory enumeration, chunked/resumable file transfer, recursive delete, process enumeration/termination, up to 10 concurrent interactive shells, shared-object module loading, config override, reboot, and port forwarding/proxying.
C2 relays are compromised Taiwanese edge devices on Chunghwa Telecom (AS3462): a Synology NAS (59.125.211.65), an SMB network appliance (122.116.138.33) and a Dahua XVR5116HS-I3 recorder (1.34.200.85), all with byte-identical PPTP (TCP/1723) banners, indicating a dual-purpose design: outbound SMTP-disguised implant relay plus an operator-installed inbound routed VPN foothold. Rapid7 assesses the relay pattern as consistent with China-nexus operational relay box (ORB) networks described in the April 2026 CISA/NCSC-UK advisory AA26-113A, but did not confirm membership in any named network (LapDogs/UAT-7810, SPACEHOP, FLORAHOX). Attribution of the BPFDoor cluster to Chinese-linked telecom espionage is reported as likely; no CVE or initial-access vulnerability is stated in the sources.
MITRE ATT&CK techniques used in TL-2026-2875
Defense Evasion
T1027.013 Obfuscated Files or Information: Encrypted/Encoded File; T1036.004 Masquerading: Masquerade Task or Service; T1036.005 Masquerading: Match Legitimate Resource Name or Location; T1070.004 Indicator Removal: File Deletion; T1070.006 Indicator Removal: Timestomp; T1205.002 Traffic Signaling: Socket Filters; T1480 Execution Guardrails
Discovery
T1057 Process Discovery; T1082 System Information Discovery
Execution
T1059.004 Command and Scripting Interpreter: Unix Shell; T1129 Shared Modules
Command and Control
T1071.003 Application Layer Protocol: Mail Protocols; T1090 Proxy; T1571 Non-Standard Port; T1573.001 Encrypted Channel: Symmetric Cryptography
Resource Development
Affected products and versions in BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate
- SpamSniper (South Korean anti-spam software) — Linux mail security appliances (impersonated)
Vulnerable versions: Impersonated by malware; no product vulnerability stated - ShareTech — Mail security appliances (impersonated by dropper)
Vulnerable versions: Impersonated by malware; no product vulnerability stated - Synology — NAS (compromised as relay)
Vulnerable versions: Relay at 59.125.211.65 running exposed MariaDB 5.5.62 - Dahua — XVR5116HS-I3 DVR (compromised as relay)
Vulnerable versions: Relay at 1.34.200.85
Remediation for BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate
Immediate actions
- Hunt for processes whose /proc/<pid>/exe resolves to (deleted), especially daemon-named processes (watchdogd, chronyd, polkitd, rsyslogd, crond, NetworkManager, abrtd) under /sbin
- Identify unexpected PF_PACKET raw sockets with classic BPF filters on hosts that are not packet-capture systems
- Alert on outbound TCP/25 from non-mail processes and on mail-role hostnames resolving to consumer/embedded device IPs
- Check for /var/run/spamsniper.pid, /HDD/ms6x2xTo64/, /addpkg/sbin/update, /addpkg/sbin/agetty and /var/lib/.db, .sencha, .us, .a
- Block or investigate the listed domains and relay IPs
Workarounds
- Network-segment mail security appliances and disallow unsolicited inbound traffic to the appliance management plane
Longer-term hardening
- Restrict outbound SMTP so only designated MTAs can reach TCP/25
- Retire or isolate end-of-life NAS, DVR and edge appliances exposed to the internet
- Monitor for PPTP (TCP/1723) listeners on appliances where it is not expected
- Collect auditd/EDR telemetry for socket(AF_PACKET), setsockopt(SO_ATTACH_FILTER) and prctl(PR_SET_NAME)
Timeline of BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate
- Rapid7 publishes 'BPFDoor: Telecom Networks Sleeper Cells' (March 2026; day not specified in source)
- CISA/NCSC-UK advisory AA26-113A on China-nexus ORB networks built from end-of-life NAS, edge appliances and DVRs (April 2026; month-level date used)
- Rapid7 publishes 'Stealthy BPFDoor Variants are a Needle That Looks Like Hay' introducing BPFDoor controller source code (April 2026; day not specified)
- Dark Reading and other outlets report the campaigns, noting likely Chinese-linked espionage against telecoms
- Rapid7 publishes 'SMTP is the key: BPFDoor and AVERAT hitting the network edge' documenting SpamSniper- and ShareTech-impersonating implants
- Threat ingested into Threadlinqs platform; no CVE or initial-access vulnerability identified in sources
Sources cited for BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate
- SMTP is the key: BPFDoor and AVERAT hitting the network edge
- Malicious Linux Implants Mimic Asian Mail Security Products
- Malicious Linux Implants Mimic Asian Mail Security Products (daily.dev mirror)
- SMTP is the key: BPFDoor and AVERAT hitting the network edge (daily.dev mirror)
- BPFDoor and AVERAT Mimic Email Security Appliances to Hide Linux Backdoors (Mallory)
- New Linux malware mimics network edge appliances to evade detection (SC Media)
- SMTP is the key: BPFDoor and AVERAT hitting the network edge (hendryadrian mirror)
Detection coverage for TL-2026-2875
As of 2026-10-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2875 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.