Malware, Network Security, Threat Intelligence

New Linux backdoors disguise traffic as email, hide as legitimate services

A 3D-Illustration of the word Linux on metallic cubes

Per Infosecurity Magazine. Sophisticated Linux backdoors are targeting telecom and network-edge appliances in South Korea and Taiwan, employing stealthy tactics to evade detection by disguising their malicious traffic as email and their processes as legitimate services on compromised devices.

Researchers at Rapid7 have identified a new variant of the BPFDoor malware and a BPF Rekoobe build targeting South Korean entities, alongside a dropper and six builds of an implant named AVERAT deployed against Taiwanese appliances. AVERAT utilizes Transmission Control Protocol (TCP) port 25 and the Simple Mail Transfer Protocol (SMTP) to communicate, making its outbound traffic indistinguishable from legitimate email on mail security gateways. The malware can perform file transfers, terminate processes, establish up to ten concurrent shell sessions, and create proxy or port-forwarding channels. The BPF Rekoobe sample and a South Korean BPFDoor variant impersonate SpamSniper, an anti-spam product, while other BPFDoor samples mimic processes on Oracle-based telecom platforms. The compromised devices, including Synology NAS, small-business appliances, and Dahua video recorders, are used as relays, potentially forming operational relay box (ORB) networks. Rapid7 advises investigating unusual packet sockets, outbound port 25 connections from non-mail services, and processes masquerading as system daemons, while also recommending restricted management access to edge appliances.

Source: Infosecurity Magazine

An In-Depth Guide to Network Security

Get essential knowledge and practical strategies to fortify your network security.

You can skip this ad in 5 seconds