Cutting-edge malware developers have been using their intimate knowledge of Korean and Taiwanese network edge appliances to build Linux implants that infect and mimic them to an extraordinary degree.
It’s common enough for malicious software to imitate legitimate software, superficially. An unwelcome program might name itself after something it expects in its target environment, so that if a passerby spots it, they might not think much of it. A few new Linux backdoors go further than this, though, by imitating the filenames, firewall-allowed traffic, and other specific operating habits of the popular Asian email security appliances they infect.
Research from Rapid7 Intelligence, a new offensive engine launched today, documented two adjacent, in some ways overlapping campaigns involving these backdoors. One cluster includes new variants on the infamous “BPFdoor” implant, and a new BPFdoor-esque iteration of the old “Rekoobe” remote access Trojan (RAT). The other is built around a novel tool called “AVERAT.”
The Korea Campaign: BPFdoor, Rekoobe
For years now, “BPFdoor” has been one of the stealthier backdoors known to the cybersecurity industry. In May, Rapid7 documented two of its newest, ultra-quiet listening and propagating techniques. In short: The malware lay dormant, waiting for an activation code located at a specific byte within incoming, seemingly harmless HTTPS requests. And it could propagate data to specific, identified computers deeper within target organizations by inserting a code into innocuous Internet Control Message Protocol (ICMP) pings.
Every time researchers document BPFdoor publicly, it adapts; this allows its Chinese handlers to continue spying on global telecommunications companies. The newest BPFdoor variants build on its existing stealth techniques by mimicking a South Korean anti-spam software called “SpamSniper.” One additional BPFdoor sample disguises itself as a background process one might expect to see in Oracle-backed telecom subscriber and provisioning platforms.
Researchers also found that another longstanding Linux RAT, “Rekoobe,” has been masquerading as SpamSniper, as part of the same general campaign. The two malware tools take their mimicry seriously, copying the legitimate software’s Process ID (PID) file, system services, and commonly used Linux services. Rekoobe also mimics BPFdoor, in a way, by copying its passive Berkeley Packet Filtering (BPF) activation technique.
That these programs chose SpamSniper as a muse is no accident, and this likely indicates which sorts of targets they’re being aimed at: According to Japanese B2B search platform IPROS, SpamSniper was used by more than 6,000 organizations as of July 2023. Jiran Group, the vendor, boasts on its website about supplying customers across the Asia-Pacific region, including central government ministries and public institutions in South Korea.
The Taiwan Campaign: AVERAT
Confusingly, the new Rekoobe RAT shares cryptography routines with a malware dropper belonging to seemingly a separate campaign. The dropper adopts the identity of a ShareTech Information appliance. ShareTech is a Taiwanese mail security vendor that, according to its website, services large enterprises, educational institutions, and government entities. It claims to enjoy “tens of thousands of enterprise users in Taiwan,” and, according to its LinkedIn page, organizations in India, Indonesia, Japan, Kenya, and Thailand.
The ShareTech dropper installs two programs: itself — again, in a loop, in case anything goes wrong — and AVERAT. Then it waits 10 seconds and deletes all of the malicious files it dropped, leaving only the running processes in place to limit leftover evidence.
AVERAT is a mostly straightforward modular RAT. Its most effective quality, which it shares with the new Rekoobe, is using Transmission Control Protocol (TCP) Port 25 for command-and-control (C2). Port 25, the traditional network port for the Simple Mail Transfer Protocol (SMTP), allows AVERAT and Rekoobe to communicate with their puppet masters in a way that blends with normal email traffic. AVERAT also makes sure to use typical SMTP conventions before beginning an encrypted session. In the end: All it looks like is email activity going to some arbitrary mail exchanger (MX) — an utterly normal occurrence in any enterprise environment.
As an added bonus: In case anyone goes looking for the servers these programs are communicating to, they’ll instead run into popped edge devices — digital video recorders (DVRs), network-attached storage (NAS) units, etc. — used as operational relay points.
This is the first research conducted by Rapid7 Intelligence, the new offensive engine combining Rapid7’s threat intelligence, vulnerability research, and Rapid7 Labs expertise to provide enterprise defenders with AI-supported insights to anticipate and disrupt attacks.
Why Exploiting SEGs Works
Infecting and blending into secure email gateways (SEGs) turns out to be a pretty good strategy for intelligence gathering, says Christiaan Beek, vice president of Rapid7 Intelligence.
First off, SEGs occupy a privileged position in targeted networks. “These devices sit at the network edge, on the path between the Internet and the core, and are often trusted by the firewall rules around them. A foothold there is well placed for long-term access, particularly in telecom environments,” Beek explains.
Even more problematic, “These appliances are closed, vendor-managed boxes that typically can’t run endpoint detection and response (EDR) or other endpoint agents. Few organizations monitor them closely, so an implant can sit there for a long time,” he says.
Adding to the pile, “File-based detection doesn’t work here because nothing persists in the directory. Network detection takes more effort too, because you have to fingerprint the implant’s fixed Transport Layer Security (TLS) handshake rather than just watching a port, and the port can be changed at runtime,” he says. “Many organizations also lack a baseline of what normal outbound mail traffic from their appliances looks like, which is what makes the anomaly detectable.” Without this baseline, malware C2 can simply float with the current alongside an organization’s regular mail flow.
Perhaps counterintuitively, the easiest way to detect these ultra-stealthy implants is by simply looking for them.
“It’s straightforward on any Linux system where you have shell access or an agent,” Beek says. “Look for processes whose executable has been deleted (they show a ‘(deleted)’ suffix under /proc), unexpected raw packet sockets, and known dropper artifacts such as the /HDD/ms6x2xTo64/ directory. Restricting management access to edge devices and monitoring outbound port 25 from anything that isn’t a mail service are also routine controls for a mature security team.”

No responses yet