# BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate SpamSniper and ShareTech Mail Security Appliances (SMTP/TCP 25 C2)

> Rapid7 documents two overlapping Linux implant campaigns that impersonate Asian email security appliances: new BPFDoor variants and a modified Rekoobe backdoor posing as South Korean anti-spam software SpamSniper, and a novel modular RAT, AVERAT, posing as Taiwanese ShareTech mail security appliances. Both abuse TCP port 25 for C2 and relay through compromised edge devices (Synology NAS, DVRs, SMB appliances). The BPFDoor cluster targets South Korean telecom/mail environments and is likely tied to Chinese-linked espionage.

- **Published:** 2026-10-03T00:00:00Z
- **Last reviewed:** 2026-10-03T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2875
- **ID:** TL-2026-2875
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 27 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Rapid7 (published 2026-10-02, 'SMTP is the key: BPFDoor and AVERAT hitting the network edge') analyzes a cluster of Linux malware that copies the filenames, PID files, process names and firewall-permitted traffic profile of email security appliances. Two overlapping campaigns are described.

Campaign 1 (South Korea): two new BPFDoor variants and one modified Rekoobe variant impersonate SpamSniper. The BPFDoor builds reuse the SpamSniper PID file (/var/run/spamsniper.pid) as a mutex and rotate through ten Linux daemon names (watchdogd, chronyd, polkitd, rsyslogd, crond, NetworkManager, python/tuned, scsi_tmf_6, charger_manager, kaluad_sync). They remain dormant until a magic value is observed in packets delivered through a raw packet socket with an attached classic BPF filter (variant magic values 0x6693 UDP, 0x4274 TCP, 0x7820 ICMP), with a new variant also supporting HTTP tunneling over HTTPS POST. The Rekoobe variant (652508a9...) installs a BPF filter on TCP/UDP/SCTP over IPv4 and UDP over IPv6 for port 25, spoofs SpamSniper process paths (/sniper/bin/crond, /sniper/bin/earsd, /sniper/apache/bin/httpd, /sniper/snipe/bin/snipe-smtpd, /sniper/autorun/rblsmtpd) and suppresses shell history (VIMINIT, HISTFILE=/dev/null, HISTSIZE=0, HISTFILESIZE=0). Data-plane variants spoof ora_ppmond, /sniper/snipe/bin/dtnpd and /sniper/bin/ofgmd and embed Tiny Shell.

Campaign 2 (Taiwan): AVERAT, a novel modular RAT, ships in six builds against embedded appliances, Synology NAS and CCTV/DVR devices, delivered by a ShareTech-themed dropper whose payload is AES-128-ECB encrypted with a key derived from SHA1('ShareTech'). The dropper is gated by /tmp/flag, runs /HDD/ms6x2xTo64/updIptable.php, copies two binaries into /sbin under alternate names (ntpdate, udevds), launches them and unlinks each about ten seconds later while processes keep running; payloads land at /addpkg/sbin/update and /addpkg/sbin/agetty. AVERAT beacons every 600-699 seconds over a SMTP/STARTTLS-looking channel on TCP/25, reporting hostname, user, OS version, interfaces and logged-in users, and persists 276-byte encrypted state in /var/lib/.db (or .sencha, .us, .a). Its command set includes directory enumeration, chunked/resumable file transfer, recursive delete, process enumeration/termination, up to 10 concurrent interactive shells, shared-object module loading, config override, reboot, and port forwarding/proxying.

C2 relays are compromised Taiwanese edge devices on Chunghwa Telecom (AS3462): a Synology NAS (59.125.211.65), an SMB network appliance (122.116.138.33) and a Dahua XVR5116HS-I3 recorder (1.34.200.85), all with byte-identical PPTP (TCP/1723) banners, indicating a dual-purpose design: outbound SMTP-disguised implant relay plus an operator-installed inbound routed VPN foothold. Rapid7 assesses the relay pattern as consistent with China-nexus operational relay box (ORB) networks described in the April 2026 CISA/NCSC-UK advisory AA26-113A, but did not confirm membership in any named network (LapDogs/UAT-7810, SPACEHOP, FLORAHOX). Attribution of the BPFDoor cluster to Chinese-linked telecom espionage is reported as likely; no CVE or initial-access vulnerability is stated in the sources.

## MITRE ATT&CK

- T1584.008 Compromise Infrastructure: Network Devices
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1129 Shared Modules
- T1480 Execution Guardrails
- T1205.002 Traffic Signaling: Socket Filters
- T1070.004 Indicator Removal: File Deletion
- T1070.006 Indicator Removal: Timestomp
- T1036.005 Masquerading: Match Legitimate Resource Name or Location
- T1036.004 Masquerading: Masquerade Task or Service
- T1027.013 Obfuscated Files or Information: Encrypted/Encoded File
- T1082 System Information Discovery
- T1057 Process Discovery
- T1071.003 Application Layer Protocol: Mail Protocols
- T1573.001 Encrypted Channel: Symmetric Cryptography
- T1090 Proxy
- T1571 Non-Standard Port

## Sources

- [SMTP is the key: BPFDoor and AVERAT hitting the network edge](https://www.rapid7.com/blog/post/tr-smtp-is-the-key-bpfdoor-averat-hitting-the-network-edge/)
- [Malicious Linux Implants Mimic Asian Mail Security Products](https://www.darkreading.com/threat-intelligence/malicious-linux-implants-mimic-asian-mail-security)
- [Malicious Linux Implants Mimic Asian Mail Security Products (daily.dev mirror)](https://daily.dev/posts/malicious-linux-implants-mimic-asian-mail-security-products-qrfnmbqg9)
- [SMTP is the key: BPFDoor and AVERAT hitting the network edge (daily.dev mirror)](https://daily.dev/posts/smtp-is-the-key-bpfdoor-and-averat-hitting-the-network-edge-qtcqttgj6)
- [BPFDoor and AVERAT Mimic Email Security Appliances to Hide Linux Backdoors (Mallory)](https://mallory.ai/stories/01a0fd07-cb1b-7ddb-9a18-cdbecd0507cf)
- [New Linux malware mimics network edge appliances to evade detection (SC Media)](https://www.scworld.com/brief/new-linux-malware-mimics-network-edge-appliances-to-evade-detection)
- [SMTP is the key: BPFDoor and AVERAT hitting the network edge (hendryadrian mirror)](https://www.hendryadrian.com/smtp-is-the-key-bpfdoor-and-averat-hitting-the-network-edge/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2875
