Rapid7 finds Linux malware disguised as Korean and Taiwanese mail security tools
Rapid7 researchers identified two malware campaigns using Linux backdoors that closely mimic legitimate Asian network security appliances. One campaign involves new variants of the BPFdoor implant and a modified Rekoobe trojan designed to impersonate South Korea's SpamSniper anti-spam software, while the other uses a newly identified tool called AVERAT. The implants replicate filenames, firewall-permitted traffic patterns, and operational behaviors of the genuine products to avoid detection.
GoKawiil's interpretation of the reporting above, not reported fact.
The level of mimicry suggests attackers have detailed knowledge of specific vendor products, which could make these implants far harder for defenders to spot through normal monitoring. Rapid7 has linked earlier BPFdoor activity to Chinese actors targeting global telecommunications firms, so continued evolution of the malware indicates an ongoing, adaptive espionage effort rather than a one-off intrusion.
- Rapid7 documented two malware campaigns using Linux implants disguised as Asian mail security appliances
- New BPFdoor and Rekoobe variants impersonate South Korea's SpamSniper software down to filenames and network behavior
- A separate tool called AVERAT is part of a related but distinct campaign tracked by researchers
Source: darkreading.com — Nate Nelson, 2026-10-02
Published there as: “Malicious Linux Implants Mimic Asian Mail Security Products”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.