// 1 CRITICAL · 1 CVE · 2 EXPLOIT · 1 ADVISORY IN THE LAST 24H→
Rapid7 has tracked new variants of the BPFDoor backdoor targeting mail gateways and telecom appliances in South Korea and Taiwan. The research, published October 2, 2026, proves that the absence of alerts does not equal absence of compromise: the malware remains passive until it receives a specific magic packet, invisible to conventional port scans. The stakes exceed a single incident: a compromised telecom provider exposes entire nations to tracking and mobile traffic disruption risks.
{"main_topic":"cybersecurity","topics":["cybersec","malware","linux","network"]}

Rapid7 has tracked new variants of the BPFDoor backdoor targeting mail gateways and telecom appliances in South Korea and Taiwan. The research, published October 2, 2026, proves that the absence of alerts does not equal absence of compromise: the malware remains passive until it receives a specific magic packet, invisible to conventional port scans. The stakes exceed a single incident: a compromised telecom provider exposes entire nations to tracking and mobile traffic disruption risks.

Key Takeaways
  • BPFDoor creates a raw PF_PACKET socket with a kernel-level BPF filter to capture magic UDP bytes (0x6693), TCP (0x4274), and ICMP (0x7820), without opening listening ports detectable by netstat or lsof.
  • Rapid7 identified six AVERAT builds against Taiwanese appliances and BPF Rekoobe variants against South Korean targets, with specific process masquerading via impersonation of SpamSniper, a Korean anti-spam product.
  • The latest variants encapsulate the magic packet in standard HTTPS POST requests, exploiting SSL offloading in telecom environments to evade deep packet inspection.
  • AVERAT establishes its C2 channel on TCP port 25 with SMTP/STARTTLS traffic indistinguishable from legitimate traffic in flow records; check-in occurs every 600–699 seconds.

The Paradox of the Invisible Edge

Network edge devices — mail security gateways, firewalls, VPN appliances — are designed to filter traffic, not to be inspected. According to the cited source, these are "closed, vendor-managed boxes that typically can't run endpoint detection and response (EDR) or other endpoint agents." This architecture creates a structural discontinuity: the organization is legally and reputationally responsible for its network security, but lacks the technical visibility to exercise that control.

Christiaan Beek, VP of Rapid7 Intelligence, framed the dilemma explicitly: "If an appliance can sit between your organization and the internet, but you cannot independently verify what it is doing, then you are effectively outsourcing trust without outsourcing the accountability." The consequence is that CISOs receive green dashboards that hide a reality they cannot verify exists.

How BPFDoor Exploits the Edge Black Hole

The core technical mechanism is the passive backdoor based on Berkeley Packet Filter. The implant creates a raw PF_PACKET socket and installs a 16-instruction BPF filter — or 26 instructions in the BPF Rekoobe sample — that captures only packets containing specific magic bytes. This architecture eliminates two traditional indicators of compromise: there is no constant beaconing to a C2 server, and no listening ports visible to standard network monitoring tools.

The attack chain documented by Rapid7 uses a dropper that derives the encryption key from the string 'ShareTech' and resides in the appliance's additional packages directory. The dropper writes a shell script that stages both payloads in /sbin as ntpdate and udevds, launches them, and deletes the binary files after 10 seconds. The result is a process without a disk image: the file is /proc/(deleted), the malware is running, but there is no persistent trace in the filesystem for conventional scans.

The masquerading is regionalized and context-aware. Variants targeting South Korean systems impersonate the SpamSniper PID file and rotate among ten Linux daemon names. The BPF Rekoobe sample sets process names via argv rewriting, including /sniper/bin/crond -n and /sniper/apache/bin/httpd -k start. Each sample is calibrated to the target system's vendor software.

SMTP as a Tunnel: Traffic That Doesn't Look Anomalous

The evolutionary novelty of the 2026 variants is the use of legitimate protocols as C2 channels. AVERAT connects on TCP port 25 and speaks SMTP, sending EHLO and requesting STARTTLS before initiating the encrypted session. On a mail security gateway, where server-to-server relay traffic is the appliance's primary function, this flow is indistinguishable from legitimate work in flow records. As Rapid7 reports via Infosecurity Magazine: "On a mail security gateway, where outbound mail is the device's core job, the traffic is indistinguishable from legitimate work in flow records."

AVERAT checks in every 600–699 seconds with commands that include file transfer, process termination, up to ten concurrent shell sessions, and proxy/port-forwarding channels. Three builds report to hardcoded addresses on compromised third-party devices in Taiwan: a Synology NAS, an obsolete small-business appliance, and a Dahua video recorder. All three ran an identical PPTP VPN service that Rapid7 believes was installed by the operators, opening a route into the victim network.

The C2 relay matches the device profile of an April 2026 CISA advisory on covert networks with a China nexus. Rapid7 found no overlap with any named ORB network, and attribution remains ongoing.

"No outbound traffic and no alerts do not mean the system is clean. A green dashboard is not the same thing as proof." — Christiaan Beek, VP Rapid7 Intelligence

Why It Matters

The dossier does not specify specific remediation measures or vendor guidelines for the compromised target appliances. No infrastructure overlaps emerge linking the BPFDoor/AVERAT activity to a named threat actor group at this time. The exact scale of infections remains unquantified, as does the precise initial access vector for the documented compromises.

The source does not clarify whether the 2026 variants represent the same historical BPFDoor actor or different operators who have acquired or relaunched the toolkit. An effective start date for the AVERAT campaign against Taiwan is not documented.

What the dossier documents clearly is the systemic risk. Beek emphasized that "compromising a telecom provider is not about the telecom provider itself; we need to realize that capabilities a threat actor would have after doing so, ranging from tracking people to disrupting the mobile traffic, could impact an entire nation." The compromise is not a corporate cybersecurity problem with internal consequences: it is an event with sovereign-scale impact surface.

Questions and Answers

Why do BPF filters make BPFDoor invisible to standard tools?
BPF filters operate at the kernel level on the raw PF_PACKET socket, before the packet reaches the TCP/IP stack. Because no listening socket is opened on the conventional stack, netstat and lsof report no port associated with the process. The malware is present in memory but leaves no traces in the network namespace visible to standard administration tools.

What distinguishes the 2026 BPFDoor variants from the original 2022 version?
The documented addition is the encapsulation of the magic packet in standard HTTPS POST requests with mathematical padding to ensure the string '9999' lands exactly at offset 26 of the TCP payload, bypassing edge proxies and SSL offloading. The variants also include masquerading specific to regional software like SpamSniper and the use of SMTP/STARTTLS as a C2 channel.

What does the term 'right-to-audit' mean in the context of edge appliances?
According to the brief's editorial angle, it refers to the CISO's contractual ability to demand independent, verifiable telemetry from appliance vendors, rather than accepting only vendor-provided metrics. The dossier does not, however, specify concrete contractual examples or regulatory frameworks.

Information is based on the cited source and current as of publication.

Sources


Sources and references
  1. helpnetsecurity.com
  2. rapid7.com
  3. bleepingcomputer.com
  4. infosecurity-magazine.com
  5. thehackernews.com
  6. cve.org