hacker-news · Crawled Oct 6, 2026

Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan

4 IoCs 1 Actors 3 Malware
Read original article ↗

AI Summary

Linux backdoors have been observed targeting telecom and network appliances in South Korea and Taiwan by impersonating legitimate email security tools such as SpamSniper and ShareTech to evade detection. The threat involves a new variant of BPFDoor and a previously undocumented Linux implant named AVERAT, both using process name spoofing and C2 over SMTP on port 25. The BPFDoor variants are linked to the Red Menshen threat group and use BPF-based magic packet triggering wrapped in HTTPS POST requests to bypass deep packet inspection. AVERAT is deployed via a dropper that decrypts payloads using the key 'ShareTech' and supports extensive post-compromise capabilities including shell access, file upload/download, and process manipulation.

AI-extracted · verify before operational use

Extracted Entities 4 found

Indicators of Compromise 4 extracted

Type Value Detail
Domain mx[.]zxopfds[.]com Details →
Filename udevds Details →
Filename ntpdate Details →
Filename ora_ppmond Details →

MITRE ATT&CK TTPs 7 techniques