Overview of BPFDoor HTTP-tunneled trigger flow through edge proxy
At a Glance
| Malware family | BPFDoor variants, a BPF-enabled Rekoobe build, a dropper, and six AVERAT builds |
| Threat actor | Not named by Rapid7; infrastructure matches China-nexus covert network patterns (suspected, not confirmed) |
| Targets | Telecom and network-edge operators in South Korea and Taiwan; victim counts not disclosed |
| Delivery vector | Installed after prior access; initial entry not described |
| Key capabilities | Passive packet sniffing, fileless execution, SMTP-disguised C2, remote shell, file transfer, proxying |
| Sources | Rapid7; CISA and NCSC-UK joint advisory AA26-113A |
TL;DR
Attackers are planting Linux backdoors on telecom and mail appliances that blend into each vendor’s own software. The tools wait silently for special packets or send traffic dressed as email. Their relay servers are hacked home and small-business devices in Taiwan.
Delivery
Rapid7 does not describe how the attackers first get in. The dropper it analyzed has no network code at all. Instead, it is “a local installer, run after access is already established.”
The dropper appears built for ShareTech appliances. Strikingly, its encryption key comes from a hash of the word “ShareTech.” The operators, Rapid7 notes, “seeded their own key derivation with the target vendor’s name.”
Infection Chain
A Dropper That Leaves Nothing Behind
The dropper writes a shell script to the appliance’s storage drive and runs it. The script copies two programs into a system folder under harmless names. It starts both, then deletes each file ten seconds later. The processes keep running from memory alone. As a result, a responder searching the disk “finds nothing at all.”
One of those programs is the dropper itself. It relaunches as a watchdog that rewrites the script if anyone removes it. The second is the AVERAT implant. Rapid7 found no persistence code, because the appliance’s own package startup likely relaunches the dropper at boot.
BPFDoor Waits for a Secret Knock
BPFDoor uses a Berkeley Packet Filter to watch network traffic without opening a port. It wakes only when a “magic packet” arrives. Then it either connects back to the sender or opens a shell.
The new South Korean variant poses as SpamSniper, a Korean anti-spam product. It also rotates through ten common Linux service names. Another sample mimics Oracle-based telecom subscriber platforms. That disguise only looks normal on hosts that actually run such systems.
Rekoobe Listens on the Mail Port
A related Rekoobe-based backdoor waits for magic packets on port 25, the standard mail port. Firewalls in front of mail appliances usually allow that traffic. So the trigger reaches the implant before any deeper inspection. In Rapid7’s words, “the implant authors understood exactly what traffic profile would be invisible on this specific class of host.”
Command-and-Control and Data Theft
AVERAT Speaks SMTP
AVERAT connects outbound on port 25 and opens with normal mail commands. Only after that does it start its own encrypted session. On a mail gateway, outbound mail traffic is routine. Therefore, the implant’s traffic looks like the device doing its job.
The implant checks in every 10 to 11 minutes. It reports the hostname, user, OS version, and network details. Its commands let operators browse files, upload and download data, and run up to ten shells at once. It can also turn the appliance into a proxy and load extra modules.
Controller Hides Triggers in Web Traffic
Rapid7 also reconstructed the source code of a BPFDoor controller. Older versions sent raw magic bytes that security tools learned to spot. The new controller tucks the trigger inside fake HTTPS login requests. Telecom proxies decrypt that traffic and pass it along to the infected host.
Hijacked Devices as Relays
AVERAT’s servers are not attacker-owned machines. They are hacked devices on Taiwanese broadband lines, including a NAS, an outdated network appliance, and a CCTV recorder. All three run an extra VPN service that Rapid7 believes the operators installed.
Attribution
Rapid7 does not name a threat actor. However, the relay setup matches the device types that CISA, NCSC-UK, and partners linked to China-nexus covert networks in their April 2026 advisory. That advisory warned about large networks of hacked routers and IoT devices used to hide attacks. Rapid7 found no overlap with any specific named network. So the China link remains suspected, not confirmed.
Defense and Detection Guidance
Disk scans will likely miss the BPFDoor backdoor and AVERAT, since no payload stays on disk. Rapid7 recommends these steps instead:
- Hunt for Linux processes whose executable file has been deleted.
- Look for executable memory with no backing file on disk.
- Investigate raw packet sockets and BPF filters on systems that do not need packet capture.
- Review outbound port-25 traffic from processes that are not mail services.
- Flag mail traffic to hosts that resolve to consumer or embedded devices.
- Restrict management access to routers, DVRs, and other edge appliances.
Finally, preserve short-lived binaries and process details during any investigation. With fileless implants like these, memory is often the only evidence left.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!