// 1 CRITICAL · 5 ZERO-DAY · 5 CVE · 2 EXPLOIT IN THE LAST 24H→
Rapid7 has documented new variants of the BPFDoor Linux backdoor and the AVERAT implant deployed against telecom network-edge operators. The samples show deep customization — each variant is pre-adapted to the victim's specific software, from South Korea's SpamSniper anti-spam product to Taiwan's ShareTech appliances — and leverages legitimate SMTP traffic for covert payload activation.

Rapid7 published a detailed technical analysis on September 29, 2026, covering new variants of the BPFDoor Linux backdoor and an implant dubbed AVERAT, both deployed against network-edge operators in the telecommunications sector. The analyzed samples show a significant level of customization: each variant is pre-adapted to the specific software running on the victim's system, from the South Korean anti-spam product SpamSniper to Taiwanese ShareTech appliances, and leverages legitimate SMTP traffic for covert payload activation.

Key Takeaways
  • Rapid7 tracked new BPFDoor variants, a BPF Rekoobe build for South Korean targets, and 6 AVERAT implant builds against Taiwanese appliances, all with regionalized target-software masquerading.
  • The infection chain is fileless: a dropper writes payloads to /sbin as ntpdate and udevds, launches them, and deletes the files after 10 seconds, leaving processes running without a disk image.
  • Activation now uses HTTPS POST tunneling with mathematical padding to ensure the string '9999' lands at offset 26, and SMTP magic packets with source/destination port 25 that exploit MTA relay firewall rules.
  • Passive BPF implants expose no listening sockets, rendering conventional port scans ineffective; outbound beacons hide in DNS, ordinary TCP, and SMTP traffic.

Regionalized Masquerading: From Generic to Vendor-Aware

The most significant technical development is not the BPF mechanism itself, but the precision of the mimicry. According to Rapid7 research, every sample is aware of the vendor software running on the targeted system and implements process spoofing accordingly. BPFDoor variants targeting South Korean systems impersonate the SpamSniper PID file — an anti-spam product used in South Korea — and rotate among 10 Linux daemon names. The process names are drawn from an encrypted table and set via argv rewriting, including /sniper/bin/crond -n, /sniper/bin/earsd --start, /sniper/apache/bin/httpd -k start, and /sniper/snipe/bin/snipe-smtpd.

For Taiwanese appliances, the dropper derives the encryption key from the string 'ShareTech' and writes to the appliance's add-on package directory. The 6 AVERAT builds documented by Rapid7 are deployed against this ecosystem. The mutex /var/run/spamsniper.pid and sample provenance instead tie the BPF Rekoobe build to the South Korean cluster. This specialization indicates operators conduct deep reconnaissance before deployment, making generic signature-based detection insufficient.

"The common thread is regionalized disguise: each sample is aware of the vendor's software running on the targeted systems and implements process spoofing accordingly" — Rapid7 Threat Research

From Raw Packets to SMTP: The Evolution of the Activation Channel

Previous BPFDoor variants used raw 'magic bytes' in TCP or UDP headers: 0x6693 for UDP, 0x4274 for TCP, 0x7820 for ICMP, with a 16-instruction BPF filter. After security vendors created static Suricata and Snort signatures for these patterns, operators shifted the activation vector to edge proxies.

The new controller, introduced by Rapid7 in April 2026, wraps the magic packet in standard HTTPS POST requests, exploiting the SSL offloading common in telecom environments. The web requests are mathematically padded to ensure the string '9999' lands at offset 26 of the TCP payload. The backdoor uses '9999' as a reference point, dynamically scans for the \r\n\r\n terminator, and extracts the hex-encoded command payload from the HTTP body. The dogetlogin function contains hardcoded web login paths to blend into legitimate requests. The controller spoofs the identity of /usr/sbin/abrtd via set_proc_name and PR_SET_NAME.

In parallel, on the SMTP front, the Rekoobe-based sample (hash 652508a9cf40bee883dc0e5e219dfeba71fe7dac591d01c89f74c21f73b4963f) uses a 26-instruction BPF filter that sniffs TCP, UDP, SCTP IPv4, and UDP IPv6 traffic with both source and destination ports equal to 25. On SpamSniper appliances, server-to-server SMTP traffic is the primary legitimate type; a magic packet with src=25, dst=25 matches the first MTA relay firewall rule and reaches the raw socket. Strings are protected with repeating-key XOR (uvTIgh47,@#R); the magic packet is authenticated against a 32-byte sequence.

The BPF Mechanism and Fileless Persistence

Technically, BPFDoor creates a raw PF_PACKET socket with a classic BPF filter. On a match, the implant extracts the source address and reconnects to the sender if the password is gZbpx0, opens a bind shell if the password is sT21xf, otherwise defaults to UDP knock. This passive mechanism completely avoids exposing visible listening ports on the operating system.

Persistence is achieved through fileless execution. The infection chain uses two binaries: a dropper writes a shell script to the appliance's storage mount, which stages both payloads in /sbin as ntpdate and udevds, launches them, and deletes the files after 10 seconds, leaving processes running without a disk image. The dropper re-executes as a resident watchdog. Another documented sample uses magic bytes abc00922 with a 13-instruction BPF filter and a 14-byte magic packet payload (2B 76 C0 63 83 E9 5F E1 EE 69 3F 32 CD 94).

Immediate Actions for Network Operators

For network operators managing edge appliances in the telecom sector, the Rapid7 report points to three concrete areas of focus. First: monitor internal server-to-server SMTP traffic with the same rigor applied to external HTTP/HTTPS traffic, particularly on anti-spam appliances where the flow is by-design authorized and MTA relay firewall rules can be exploited to reach BPF raw sockets.

Second: check for processes without a disk image associated with names that mimic daemons specific to the installed vendor software, such as /sniper/bin/earsd --start or /sniper/snipe/bin/snipe-smtpd on SpamSniper systems, and inspect the /sbin directory for executables with common names like ntpdate or udevds that do not match expected system packages.

Third: examine HTTPS POST traffic to edge appliances for mathematical padding patterns that place fixed strings at specific offsets in the TCP payload, particularly the presence of '9999' at offset 26 followed by the \r\n\r\n terminator and a hex-encoded body.

Attribution and Context

The activity is attributed to a China-nexus threat actor focused on government-level espionage, according to Rapid7's strategic context on Red Menshen. CISA and international partners have issued advisories on covert networks of compromised devices linked to the Chinese government, mentioning Volt Typhoon and Flax Typhoon; however, the CISA advisory does not specifically document BPFDoor, AVERAT, or the use of SMTP traffic as an activation channel. For specific technical claims, the primary source remains the Rapid7 analysis.

Telecommunications and network-edge operators are the most affected, including embedded devices such as CCTV and DVR that can reside near the network core. This positioning makes edge devices particularly sensitive: a compromise is not merely peripheral but potentially adjacent to critical infrastructure.

Analysis: When the Perimeter Is the Problem

The transition from raw magic packets to HTTPS POST tunneling and SMTP reflects evolutionary pressure from defenses. Operators did not abandon the passive BPF paradigm; they adapted it to security architectures that now filter raw traffic. SSL offloading, normally a performance optimization, becomes a blind spot in this scenario where seemingly locally managed traffic is actually routed to a waiting implant.

Regionalized masquerading signals a shift in pre-attack investment: no longer broad campaigns with generic payloads, but targeted preparation requiring access to information on installed software, likely via passive reconnaissance or prior access. For defenders, this implies that the baseline of internal SMTP traffic — typically considered trustworthy — must be treated with the same scrutiny reserved for external HTTP/HTTPS traffic, especially on anti-spam appliances where server-to-server flow is by-design authorized.

Frequently Asked Questions

What is AVERAT and how does it differ from BPFDoor?

AVERAT is a Linux implant documented by Rapid7 in 6 builds deployed against Taiwanese ShareTech appliances. It shares BPFDoor's fileless persistence mechanism and process masquerading, but is a distinct payload with its own dropper chain and encryption key derived from the target vendor.

Why is SMTP traffic particularly effective in this scenario?

Because on anti-spam appliances like SpamSniper, server-to-server SMTP traffic is the primary legitimate flow and is authorized by the firewall. A magic packet with source/destination port 25 matches MTA relay rules and reaches the BPF raw socket without generating detectable application-level anomalies.

What makes 'regionalized' masquerading more dangerous than generic masquerading?

The difference lies in precision: process names, paths, and mutexes are chosen to appear native to the specific software installed on the victim. An administrator seeing /sniper/bin/earsd --start on a SpamSniper system has no visible indication of compromise, unlike generic names such as sshd or cron.

Information is based on the cited source and current as of publication.

Sources


Sources and references
  1. rapid7.com
  2. cisa.gov