Tech News
← Home  ·  All topics

Linux Backdoors

1 GoKawiil brief on this topic

Rapid7 finds Linux malware disguised as Korean and Taiwanese mail security tools

Rapid7 researchers identified two malware campaigns using Linux backdoors that closely mimic legitimate Asian network security appliances. One campaign involves new variants of the BPFdoor implant and a modified Rekoobe trojan designed to impersonate South Korea's SpamSniper anti-spam software, while the other uses a newly identified tool called AVERAT. The implants replicate filenames, firewall-permitted traffic patterns, and operational behaviors of the genuine products to avoid detection.