Per Infosecurity Magazine. Sophisticated Linux backdoors are targeting telecom and network-edge appliances in South Korea and Taiwan, employing stealthy tactics to evade detection by disguising their malicious traffic as email and their processes as legitimate services on compromised devices.
Researchers at Rapid7 have identified a new variant of the BPFDoor malware and a BPF Rekoobe build targeting South Korean entities, alongside a dropper and six builds of an implant named AVERAT deployed against Taiwanese appliances. AVERAT utilizes Transmission Control Protocol (TCP) port 25 and the Simple Mail Transfer Protocol (SMTP) to communicate, making its outbound traffic indistinguishable from legitimate email on mail security gateways. The malware can perform file transfers, terminate processes, establish up to ten concurrent shell sessions, and create proxy or port-forwarding channels. The BPF Rekoobe sample and a South Korean BPFDoor variant impersonate SpamSniper, an anti-spam product, while other BPFDoor samples mimic processes on Oracle-based telecom platforms. The compromised devices, including Synology NAS, small-business appliances, and Dahua video recorders, are used as relays, potentially forming operational relay box (ORB) networks. Rapid7 advises investigating unusual packet sockets, outbound port 25 connections from non-mail services, and processes masquerading as system daemons, while also recommending restricted management access to edge appliances.
Source: Infosecurity Magazine
