DKDKCISSPSearch
Threat Research

Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan

Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection.

DKCISSP News DeskThe Hacker News6 Oct 2026, 11:54 pm
Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan
Image courtesy of The Hacker News. Original report
DKCISSP REPORT

Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection.

According to vendor Jiran Group, SpamSniper is advertised as "Korea's leading email security solution" that defends organizations against spam, malware, and server attacks.

However, the backdoors examined by Rapid7 have been found to go beyond imitating file names by assuming the identities of email security products like SpamSniper and ShareTech that are widely used in enterprise environments in South Korea and Taiwan.

The detection of a new BPFDoor version indicates that the threat actors behind the malware are actively refining and retooling their arsenal in response to public disclosures.

Threat actors are known to name their malicious software after a legitimate operating system component or a process as a defense evasion measure.

Interestingly, the use of TinyShell has been previously attributed to China-nexus clusters like Liminal Panda , UNC3886 (aka Fire Ant ), and Velvet Ant , all of which have singled out telecom networks and edge devices .

Organizations are recommended to review unexpected raw packet sockets and BPF filters on Linux systems that do not require packet capture, audit outbound TCP port 25 connections from processes that are not mail services, scan for processes posing as common daemons, and restrict management access to routers, DVRs and other edge appliances.

The findings demonstrate how threat actors are leveraging the privileged position occupied by secure email gateways (SEGs) for intelligence collection.

In 2023, a China-nexus threat actor codenamed UNC4841 was observed exploiting two different vulnerabilities in Barracuda Email Security Gateway (ESG) appliances ( CVE-2023-2868 and CVE-2023-7102 ) to deliver persistent backdoors.

The dropper observed in an overlapping campaign is an ELF binary that acts as a local installer for AVERAT, a modular implant that uses the Simple Mail Transfer Protocol (SMTP) for command-and-control (C2) and to obscure its malicious activity.

What happened

Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection.

According to vendor Jiran Group, SpamSniper is advertised as "Korea's leading email security solution" that defends organizations against spam, malware, and server attacks.

What changed

However, the backdoors examined by Rapid7 have been found to go beyond imitating file names by assuming the identities of email security products like SpamSniper and ShareTech that are widely used in enterprise environments in South Korea and Taiwan.

The detection of a new BPFDoor version indicates that the threat actors behind the malware are actively refining and retooling their arsenal in response to public disclosures.

Who is affected

Threat actors are known to name their malicious software after a legitimate operating system component or a process as a defense evasion measure.

Interestingly, the use of TinyShell has been previously attributed to China-nexus clusters like Liminal Panda , UNC3886 (aka Fire Ant ), and Velvet Ant , all of which have singled out telecom networks and edge devices .

Why it matters

Organizations are recommended to review unexpected raw packet sockets and BPF filters on Linux systems that do not require packet capture, audit outbound TCP port 25 connections from processes that are not mail services, scan for processes posing as common daemons, and restrict management access to routers, DVRs and other edge appliances.

The findings demonstrate how threat actors are leveraging the privileged position occupied by secure email gateways (SEGs) for intelligence collection.

Technical details

In 2023, a China-nexus threat actor codenamed UNC4841 was observed exploiting two different vulnerabilities in Barracuda Email Security Gateway (ESG) appliances ( CVE-2023-2868 and CVE-2023-7102 ) to deliver persistent backdoors.

The dropper observed in an overlapping campaign is an ELF binary that acts as a local installer for AVERAT, a modular implant that uses the Simple Mail Transfer Protocol (SMTP) for command-and-control (C2) and to obscure its malicious activity.

Located within the ShareTech appliance's "/addpkg/sbin/" add-on package directory, the ELF dropper works by deriving its encryption key from the string "ShareTech" and then using it to decrypt a shell script that's responsible for staging and executing two binaries: "ntpdate," which is the dropper itself, and "udevds," which is the AVERAT payload.

Response

The malicious artifacts include a new BPFDoor variant and a BPF Rekoobe build used against South Korean targets, and a previously unreported Linux implant dubbed AVERAT that's delivered via a dropper and deployed against Taiwanese appliances.

Attribution

The Hacker News: Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection.

What to watch next

Watch for new exploitation reports and updated indicators of compromise.

MORE IN THREAT RESEARCH

More cybersecurity reporting

Incident affecting ASOS customersNCSC-UK · 6 Oct 2026, 10:18 pmGoogle Gemini could soon get full access to your Mac’s files, apps and the webBleepingComputer · 4 Oct 2026, 4:42 amAndroid 17 Advanced Protection Locks Accessibility Services to Verified Accessibility ToolsThe Hacker News · 2 Oct 2026, 4:45 pmMicrosoft is rolling out Linux container support to WSLBleepingComputer · 30 Sept 2026, 6:10 am