Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan
Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection.

Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection.
According to vendor Jiran Group, SpamSniper is advertised as "Korea's leading email security solution" that defends organizations against spam, malware, and server attacks.
However, the backdoors examined by Rapid7 have been found to go beyond imitating file names by assuming the identities of email security products like SpamSniper and ShareTech that are widely used in enterprise environments in South Korea and Taiwan.
The detection of a new BPFDoor version indicates that the threat actors behind the malware are actively refining and retooling their arsenal in response to public disclosures.
Threat actors are known to name their malicious software after a legitimate operating system component or a process as a defense evasion measure.
Interestingly, the use of TinyShell has been previously attributed to China-nexus clusters like Liminal Panda , UNC3886 (aka Fire Ant ), and Velvet Ant , all of which have singled out telecom networks and edge devices .
Organizations are recommended to review unexpected raw packet sockets and BPF filters on Linux systems that do not require packet capture, audit outbound TCP port 25 connections from processes that are not mail services, scan for processes posing as common daemons, and restrict management access to routers, DVRs and other edge appliances.
The findings demonstrate how threat actors are leveraging the privileged position occupied by secure email gateways (SEGs) for intelligence collection.
In 2023, a China-nexus threat actor codenamed UNC4841 was observed exploiting two different vulnerabilities in Barracuda Email Security Gateway (ESG) appliances ( CVE-2023-2868 and CVE-2023-7102 ) to deliver persistent backdoors.
The dropper observed in an overlapping campaign is an ELF binary that acts as a local installer for AVERAT, a modular implant that uses the Simple Mail Transfer Protocol (SMTP) for command-and-control (C2) and to obscure its malicious activity.
What happened
Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection.
According to vendor Jiran Group, SpamSniper is advertised as "Korea's leading email security solution" that defends organizations against spam, malware, and server attacks.
What changed
However, the backdoors examined by Rapid7 have been found to go beyond imitating file names by assuming the identities of email security products like SpamSniper and ShareTech that are widely used in enterprise environments in South Korea and Taiwan.
The detection of a new BPFDoor version indicates that the threat actors behind the malware are actively refining and retooling their arsenal in response to public disclosures.
Who is affected
Threat actors are known to name their malicious software after a legitimate operating system component or a process as a defense evasion measure.
Interestingly, the use of TinyShell has been previously attributed to China-nexus clusters like Liminal Panda , UNC3886 (aka Fire Ant ), and Velvet Ant , all of which have singled out telecom networks and edge devices .
Why it matters
Organizations are recommended to review unexpected raw packet sockets and BPF filters on Linux systems that do not require packet capture, audit outbound TCP port 25 connections from processes that are not mail services, scan for processes posing as common daemons, and restrict management access to routers, DVRs and other edge appliances.
The findings demonstrate how threat actors are leveraging the privileged position occupied by secure email gateways (SEGs) for intelligence collection.
Technical details
In 2023, a China-nexus threat actor codenamed UNC4841 was observed exploiting two different vulnerabilities in Barracuda Email Security Gateway (ESG) appliances ( CVE-2023-2868 and CVE-2023-7102 ) to deliver persistent backdoors.
The dropper observed in an overlapping campaign is an ELF binary that acts as a local installer for AVERAT, a modular implant that uses the Simple Mail Transfer Protocol (SMTP) for command-and-control (C2) and to obscure its malicious activity.
Located within the ShareTech appliance's "/addpkg/sbin/" add-on package directory, the ELF dropper works by deriving its encryption key from the string "ShareTech" and then using it to decrypt a shell script that's responsible for staging and executing two binaries: "ntpdate," which is the dropper itself, and "udevds," which is the AVERAT payload.
Response
The malicious artifacts include a new BPFDoor variant and a BPF Rekoobe build used against South Korean targets, and a previously unreported Linux implant dubbed AVERAT that's delivered via a dropper and deployed against Taiwanese appliances.
Attribution
The Hacker News: Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection.
What to watch next
Watch for new exploitation reports and updated indicators of compromise.