Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan
AI Summary
Linux backdoors have been observed targeting telecom and network appliances in South Korea and Taiwan by impersonating legitimate email security tools such as SpamSniper and ShareTech to evade detection. The threat involves a new variant of BPFDoor and a previously undocumented Linux implant named AVERAT, both using process name spoofing and C2 over SMTP on port 25. The BPFDoor variants are linked to the Red Menshen threat group and use BPF-based magic packet triggering wrapped in HTTPS POST requests to bypass deep packet inspection. AVERAT is deployed via a dropper that decrypts payloads using the key 'ShareTech' and supports extensive post-compromise capabilities including shell access, file upload/download, and process manipulation.
AI-extracted · verify before operational use