Threat reportMalwareTL-2026-2875

BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate SpamSniper and ShareTech Mail Security Appliances (SMTP/TCP 25 C2)

highACTIVE

BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate (TL-2026-2875), also tracked as SMTP is the key campaign, is a high-severity malware campaign, first published 2026-10-03. It is linked to a China-nexus actor with low confidence, affects SpamSniper (South Korean anti-spam software) Linux mail security, maps to 16 MITRE ATT&CK techniques (T1027.013, T1036.004, T1036.005), and is covered by 9 detection rules and 27 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
16MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
27Indicators of compromise

Key facts for TL-2026-2875

Threat ID
TL-2026-2875
Also known as
SMTP is the key campaign
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
telecoms, email security mail gateways, network edge appliances, cctv dvr
Target regions
south korea, taiwan
Detection rules
9
Indicators of compromise
27

Malware and tooling in BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate

Malware and tooling: AVERAT, BPFDoor, Rekoobe, tsh

How BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate works

Rapid7 documents two overlapping Linux implant campaigns that impersonate Asian email security appliances: new BPFDoor variants and a modified Rekoobe backdoor posing as South Korean anti-spam software SpamSniper, and a novel modular RAT, AVERAT, posing as Taiwanese ShareTech mail security appliances. Both abuse TCP port 25 for C2 and relay through compromised edge devices (Synology NAS, DVRs, SMB appliances). The BPFDoor cluster targets South Korean telecom/mail environments and is likely tied to Chinese-linked espionage.

Rapid7 (published 2026-10-02, 'SMTP is the key: BPFDoor and AVERAT hitting the network edge') analyzes a cluster of Linux malware that copies the filenames, PID files, process names and firewall-permitted traffic profile of email security appliances. Two overlapping campaigns are described.

Campaign 1 (South Korea): two new BPFDoor variants and one modified Rekoobe variant impersonate SpamSniper. The BPFDoor builds reuse the SpamSniper PID file (/var/run/spamsniper.pid) as a mutex and rotate through ten Linux daemon names (watchdogd, chronyd, polkitd, rsyslogd, crond, NetworkManager, python/tuned, scsi_tmf_6, charger_manager, kaluad_sync). They remain dormant until a magic value is observed in packets delivered through a raw packet socket with an attached classic BPF filter (variant magic values 0x6693 UDP, 0x4274 TCP, 0x7820 ICMP), with a new variant also supporting HTTP tunneling over HTTPS POST. The Rekoobe variant (652508a9...) installs a BPF filter on TCP/UDP/SCTP over IPv4 and UDP over IPv6 for port 25, spoofs SpamSniper process paths (/sniper/bin/crond, /sniper/bin/earsd, /sniper/apache/bin/httpd, /sniper/snipe/bin/snipe-smtpd, /sniper/autorun/rblsmtpd) and suppresses shell history (VIMINIT, HISTFILE=/dev/null, HISTSIZE=0, HISTFILESIZE=0). Data-plane variants spoof ora_ppmond, /sniper/snipe/bin/dtnpd and /sniper/bin/ofgmd and embed Tiny Shell.

Campaign 2 (Taiwan): AVERAT, a novel modular RAT, ships in six builds against embedded appliances, Synology NAS and CCTV/DVR devices, delivered by a ShareTech-themed dropper whose payload is AES-128-ECB encrypted with a key derived from SHA1('ShareTech'). The dropper is gated by /tmp/flag, runs /HDD/ms6x2xTo64/updIptable.php, copies two binaries into /sbin under alternate names (ntpdate, udevds), launches them and unlinks each about ten seconds later while processes keep running; payloads land at /addpkg/sbin/update and /addpkg/sbin/agetty. AVERAT beacons every 600-699 seconds over a SMTP/STARTTLS-looking channel on TCP/25, reporting hostname, user, OS version, interfaces and logged-in users, and persists 276-byte encrypted state in /var/lib/.db (or .sencha, .us, .a). Its command set includes directory enumeration, chunked/resumable file transfer, recursive delete, process enumeration/termination, up to 10 concurrent interactive shells, shared-object module loading, config override, reboot, and port forwarding/proxying.

C2 relays are compromised Taiwanese edge devices on Chunghwa Telecom (AS3462): a Synology NAS (59.125.211.65), an SMB network appliance (122.116.138.33) and a Dahua XVR5116HS-I3 recorder (1.34.200.85), all with byte-identical PPTP (TCP/1723) banners, indicating a dual-purpose design: outbound SMTP-disguised implant relay plus an operator-installed inbound routed VPN foothold. Rapid7 assesses the relay pattern as consistent with China-nexus operational relay box (ORB) networks described in the April 2026 CISA/NCSC-UK advisory AA26-113A, but did not confirm membership in any named network (LapDogs/UAT-7810, SPACEHOP, FLORAHOX). Attribution of the BPFDoor cluster to Chinese-linked telecom espionage is reported as likely; no CVE or initial-access vulnerability is stated in the sources.

MITRE ATT&CK techniques used in TL-2026-2875

Defense Evasion

T1027.013 Obfuscated Files or Information: Encrypted/Encoded File; T1036.004 Masquerading: Masquerade Task or Service; T1036.005 Masquerading: Match Legitimate Resource Name or Location; T1070.004 Indicator Removal: File Deletion; T1070.006 Indicator Removal: Timestomp; T1205.002 Traffic Signaling: Socket Filters; T1480 Execution Guardrails

Discovery

T1057 Process Discovery; T1082 System Information Discovery

Execution

T1059.004 Command and Scripting Interpreter: Unix Shell; T1129 Shared Modules

Command and Control

T1071.003 Application Layer Protocol: Mail Protocols; T1090 Proxy; T1571 Non-Standard Port; T1573.001 Encrypted Channel: Symmetric Cryptography

Resource Development

T1584.008 Compromise Infrastructure: Network Devices

Affected products and versions in BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate

  • SpamSniper (South Korean anti-spam software) — Linux mail security appliances (impersonated)
    Vulnerable versions: Impersonated by malware; no product vulnerability stated
  • ShareTech — Mail security appliances (impersonated by dropper)
    Vulnerable versions: Impersonated by malware; no product vulnerability stated
  • Synology — NAS (compromised as relay)
    Vulnerable versions: Relay at 59.125.211.65 running exposed MariaDB 5.5.62
  • Dahua — XVR5116HS-I3 DVR (compromised as relay)
    Vulnerable versions: Relay at 1.34.200.85

Remediation for BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate

Immediate actions

  • Hunt for processes whose /proc/<pid>/exe resolves to (deleted), especially daemon-named processes (watchdogd, chronyd, polkitd, rsyslogd, crond, NetworkManager, abrtd) under /sbin
  • Identify unexpected PF_PACKET raw sockets with classic BPF filters on hosts that are not packet-capture systems
  • Alert on outbound TCP/25 from non-mail processes and on mail-role hostnames resolving to consumer/embedded device IPs
  • Check for /var/run/spamsniper.pid, /HDD/ms6x2xTo64/, /addpkg/sbin/update, /addpkg/sbin/agetty and /var/lib/.db, .sencha, .us, .a
  • Block or investigate the listed domains and relay IPs

Workarounds

  • Network-segment mail security appliances and disallow unsolicited inbound traffic to the appliance management plane

Longer-term hardening

  • Restrict outbound SMTP so only designated MTAs can reach TCP/25
  • Retire or isolate end-of-life NAS, DVR and edge appliances exposed to the internet
  • Monitor for PPTP (TCP/1723) listeners on appliances where it is not expected
  • Collect auditd/EDR telemetry for socket(AF_PACKET), setsockopt(SO_ATTACH_FILTER) and prctl(PR_SET_NAME)

Timeline of BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate

  • Rapid7 publishes 'BPFDoor: Telecom Networks Sleeper Cells' (March 2026; day not specified in source)
  • CISA/NCSC-UK advisory AA26-113A on China-nexus ORB networks built from end-of-life NAS, edge appliances and DVRs (April 2026; month-level date used)
  • Rapid7 publishes 'Stealthy BPFDoor Variants are a Needle That Looks Like Hay' introducing BPFDoor controller source code (April 2026; day not specified)
  • Dark Reading and other outlets report the campaigns, noting likely Chinese-linked espionage against telecoms
  • Rapid7 publishes 'SMTP is the key: BPFDoor and AVERAT hitting the network edge' documenting SpamSniper- and ShareTech-impersonating implants
  • Threat ingested into Threadlinqs platform; no CVE or initial-access vulnerability identified in sources

Sources cited for BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate

Detection coverage for TL-2026-2875

As of 2026-10-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2875 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
27 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats