Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Linux Backdoors: A Sophisticated Evading Tactics to Impersonate Email Security Tools


Linux backdoors impersonating email security tools have been detected in South Korea and Taiwan, using process spoofing and Berkeley Packet Filter (BPF) functionality to evade detection. The backdoors have been linked to a threat group dubbed Red Menshen, which has targeted telecom providers across the Middle East and Asia. Organizations are recommended to review their systems for these backdoors and take measures to restrict management access to routers, DVRs, and other edge appliances.

  • There has been a surge in Linux backdoors used by threat actors to evade detection.
  • The backdoors impersonate legitimate processes and security tools, making it harder to detect.
  • The threat actors use a technique called "process spoofing" to blend in and avoid detection.
  • The Linux backdoors have been discovered in South Korea and Taiwan and have been linked to a threat group called Red Menshen.
  • The backdoors use the Berkeley Packet Filter (BPF) functionality to inspect incoming network traffic and activate their behavior.
  • The threat actors are using a technique called "SSL offloading" to deliver the backdoors to the infected node.
  • The backdoors support various command codes for exfiltration, including downloading, uploading, and interacting with the shell.
  • Organizations are recommended to review their Linux systems for unexpected raw packet sockets and BPF filters.
  • The threat actors are leveraging the privileged position of secure email gateways to collect intelligence.



  • A recent surge in Linux backdoors has been observed, with threat actors employing sophisticated tactics to evade detection. The Linux backdoors, which have been discovered in South Korea and Taiwan, impersonate email security tools and seemingly legitimate processes to blend in and avoid detection.

    The threat actors have been using a technique known as "process spoofing," where they name their malicious software after a legitimate operating system component or a process as a defense evasion measure. This makes it appear less conspicuous among other Windows processes, lending it a false sense of trust, or being overlooked by an analyst during casual inspection.

    The Linux backdoors examined by Rapid7 have been found to go beyond imitating file names by assuming the identities of email security products like SpamSniper and ShareTech, which are widely used in enterprise environments in South Korea and Taiwan. SpamSniper, for instance, is advertised as "Korea's leading email security solution" that defends organizations against spam, malware, and server attacks.

    The malicious artifacts include a new BPFDoor variant and a BPF Rekoobe build used against South Korean targets, and a previously unreported Linux implant dubbed AVERAT that's delivered via a dropper and deployed against Taiwanese appliances. The BPFDoor variants seen against South Korean systems impersonate the PID file of SpamSniper, a Korean anti-spam product, and rotate through ten Linux daemon names.

    Rapid7 stated, "The BPFDoor variants seen against South Korean systems impersonate the PID file of SpamSniper, a Korean anti-spam product, and rotate through ten Linux daemon names." The malicious artifacts also include names and conventions designed to look unremarkable in the environment they target.

    The BPFdoor and its many iterations were the subject of an extensive analysis by Rapid7 earlier this year, with the activity linked to a threat group dubbed Red Menshen (aka Earth Bluecrow, DecisiveArchitect, and Red Dev 18), which has targeted telecom providers across the Middle East and Asia since 2021.

    At a high level, BPFdoor abuses the Berkeley Packet Filter (BPF) functionality to inspect incoming network traffic and activate its behavior only upon detecting a magic packet. The detection of a new BPFDoor version indicates that the threat actors behind the malware are actively refining and retooling their arsenal in response to public disclosures.

    Rapid7 stated, "Once security vendors wrote static network signatures (Suricata/Snort) to detect these Layer 4 anomalies, the operators began targeting the edge proxies." The threat actors have been using a technique known as "SSL offloading" common in telecom environments, the trigger can be delivered to the BPFDoor-infected node in a way that may evade conventional deep packet inspection.

    While some BPFDoor samples spoof SpamSniper, another artifact sets its process name to "ora_ppmond," mimicking the naming convention associated with Oracle-backed telecom subscriber and provisioning platforms. Specifically, the name appears to be a reference to "ora_pmon_*," which represents the Process Monitor (PMON) background process of an Oracle Database instance.

    Once triggered, the BPFDoor sample launches a TinyShell session and supports commands to facilitate interactive shell, upload, and download capabilities. Interestingly, the use of TinyShell has been previously attributed to China-nexus clusters like Liminal Panda, UNC3886 (aka Fire Ant), and Velvet Ant, all of which have singled out telecom networks and edge devices.

    Rapid7 explained, "These samples show BPFDoor operating as a modular framework that adapts to the telecom layer it targets, integrating TinyShell and Rekoobe logic to support exfiltration." Also observed in conjunction with the activity is a Rekoobe-based BPF backdoor that intercepts TCP/UDP/SCTP IPv4 and UDP IPv6 traffic with source and destination ports equal 25.

    Furthermore, a dropper observed in an overlapping campaign is an ELF binary that acts as a local installer for AVERAT, a modular implant that uses the Simple Mail Transfer Protocol (SMTP) for command-and-control (C2) and to obscure its malicious activity. The ELF dropper works by deriving its encryption key from the string "ShareTech" and then using it to decrypt a shell script that's responsible for staging and executing two binaries: "ntpdate," which is the dropper itself, and "udevds," which is the AVERAT payload.

    The AVERAT payload periodically polls a C2 server ("mx.zxopfds[.]com") over TCP port 25 every 600 to 699 seconds. The server details and beacon interval are extracted from an encrypted configuration. The backdoor supports a long list of command codes that include -20, to enumerate directory contents; 21, to download a file from the host, with resume support; 22, to upload a file to the host in chunks; 25, to recursively delete a file or directory tree; 30, to recursively walk a directory tree; 629, to enumerate running processes with command lines; 632, to terminate a process (SIGTERM); 842, to overwrite the C2 host and port tables at runtime; 912, to open an interactive shell session and up to 10 concurrent sessions; 914, to write a command into an open shell session; 916, to reboot the appliance; 1010, to load or unload a shared object (*.so) module, extending the implant functionality; 1576, to set the callback interval and persist it to database; 1618, to open a proxy or port-forward channel through the appliance; and unknown, to close the socket and terminate the process immediately.

    The C2 infrastructure of AVERAT, per Rapid7, matches the device-class profile typically associated with an Operational Relay Box (ORB) network, although there is no evidence it's part of any known ORBs such as LapDogs (aka UAT-7810), SPACEHOP, and FLORAHOX.

    Organizations are recommended to review unexpected raw packet sockets and BPF filters on Linux systems that do not require packet capture, audit outbound TCP port 25 connections from processes that are not mail services, scan for processes posing as common daemons, and restrict management access to routers, DVRs, and other edge appliances.

    The findings demonstrate how threat actors are leveraging the privileged position occupied by secure email gateways (SEGs) for intelligence collection. In 2023, a China-nexus threat actor codenamed UNC4841 was observed exploiting two different vulnerabilities in Barracuda Email Security Gateway (ESG) appliances (CVE-2023-2868 and CVE-2023-7102) to deliver persistent backdoors.

    "The common thread is regionalized disguise: each sample is aware of the vendor's software running on the targeted systems and implements process spoofing accordingly," the cybersecurity company said. "Passive BPF implants avoid conventional port scans; while outbound beacons hide inside ordinary DNS, TCP, and traffic, the threat actor(s) are leveraging SMTP to stay under the radar."



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Linux-Backdoors-A-Sophisticated-Evading-Tactics-to-Impersonate-Email-Security-Tools-ehn.shtml

  • https://thehackernews.com/2026/10/linux-backdoors-impersonate-email.html


  • Published: Tue Oct 6 17:36:57 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us