<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/malicious-linux-implants-mimic-asian-mail-security-products-qrfnmbqg9" -->

---
title: Malicious Linux Implants Mimic Asian Mail Security Products
description: Rapid7 researchers uncovered two overlapping campaigns deploying highly convincing Linux backdoors that mimic legitimate Asian email security appliances. One...
canonical: https://daily.dev/posts/malicious-linux-implants-mimic-asian-mail-security-products-qrfnmbqg9
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Malicious Linux Implants Mimic Asian Mail Security Products | daily.dev
og:description: Rapid7 researchers uncovered two overlapping campaigns deploying highly convincing Linux backdoors that mimic legitimate Asian email security appliances. One...
og:url: https://daily.dev/posts/malicious-linux-implants-mimic-asian-mail-security-products-qrfnmbqg9
og:image: https://api.daily.dev/og/posts/qRfNMbQG9.png
og:image:alt: Malicious Linux Implants Mimic Asian Mail Security Products
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Malicious Linux Implants Mimic Asian Mail Security Products

**[Dark Reading](https://daily.dev/sources/dr)** · 6 min read · 0 upvotes · 0 comments

## Summary

Rapid7 researchers uncovered two overlapping campaigns deploying highly convincing Linux backdoors that mimic legitimate Asian email security appliances. One campaign features new BPFdoor variants and a modified Rekoobe RAT disguising themselves as South Korean anti-spam software SpamSniper, likely tied to Chinese-linked espionage against telecoms. The other involves a novel RAT called AVERAT, which impersonates Taiwanese vendor ShareTech's mail security appliances. Both malware families abuse TCP port 25 (SMTP) for command-and-control to blend with normal email traffic, and route communications through compromised edge devices like DVRs and NAS units as relay points. Rapid7's VP Christiaan Beek explains why secure email gateways are attractive targets (closed, unmonitored, EDR-incompatible) and offers concrete detection tips, such as spotting deleted-executable processes and monitoring outbound port 25 traffic.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.darkreading.com/threat-intelligence/malicious-linux-implants-mimic-asian-mail-security>

## Questions this post answers

### How does BPFdoor hide its command-and-control traffic on compromised Linux systems?

BPFdoor stays dormant until it detects an activation code at a specific byte within incoming HTTPS requests, and it can propagate data to other internal machines by hiding codes inside ICMP pings. Newer variants also disguise themselves as South Korean anti-spam software SpamSniper, copying its process ID files and system services to blend in.

_Security teams tracking evolving backdoor techniques like these can follow research updates on daily.dev._

### Why do attackers use TCP port 25 for malware command-and-control instead of a custom port?

Port 25 is the standard SMTP port, so command-and-control traffic over it looks like ordinary email activity heading to a mail exchanger, making it hard to distinguish from normal enterprise mail flow. Malware like AVERAT and a modified Rekoobe RAT use this technique alongside typical SMTP handshake conventions before switching to an encrypted session.

_Teams hardening mail infrastructure against stealthy C2 channels can track findings like this on daily.dev._

### How can I detect a BPFdoor-style implant on a Linux secure email gateway?

Look for running processes whose executable file has been deleted, shown with a '(deleted)' suffix under /proc, since these implants delete their dropped files after launching. Also check for unexpected raw packet sockets, known dropper artifacts such as a /HDD/ms6x2xTo64/ directory, and monitor any outbound port 25 traffic from devices that are not mail services.

_Developers securing edge appliances against hidden implants can keep up with detection techniques via daily.dev._

## Similar posts on daily.dev

- [APT41 Delivers 'Undetectable' Backdoor to Steal Cloud Credentials](https://daily.dev/posts/apt41-delivers-undetectable-backdoor-to-steal-cloud-credentials-mvkzhqeh9) · Dark Reading · 0 upvotes · 0 comments
- [Trojanized ESET Installers Drop Kalambur Backdoor in Phishing Attacks on Ukraine](https://daily.dev/posts/trojanized-eset-installers-drop-kalambur-backdoor-in-phishing-attacks-on-ukraine-amw6o2ru1) · The Hacker News · 1 upvotes · 0 comments
- [Chinese hackers target telcos with new Linux, Windows malware](https://daily.dev/posts/chinese-hackers-target-telcos-with-new-linux-windows-malware-ql0h0a4gw) · BleepingComputer · 2 upvotes · 0 comments
- [SilverFox Hackers Use Go RAT, AV Killer, and Kernel Rootkit in ValleyRAT Campaign](https://daily.dev/posts/silverfox-hackers-use-go-rat-av-killer-and-kernel-rootkit-in-valleyrat-campaign-8mnjmf0s7) · Security Boulevard · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#linux](https://daily.dev/tags/linux), [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/malicious-linux-implants-mimic-asian-mail-security-products-qrfnmbqg9)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Malicious Linux Implants Mimic Asian Mail Security Products","url":"https://daily.dev/posts/malicious-linux-implants-mimic-asian-mail-security-products-qrfnmbqg9","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/malicious-linux-implants-mimic-asian-mail-security-products-qrfnmbqg9"},"datePublished":"2026-10-02T13:01:48.228Z","dateModified":"2026-10-02T13:21:29.805Z","description":"Rapid7 researchers uncovered two overlapping campaigns deploying highly convincing Linux backdoors that mimic legitimate Asian email security appliances. One...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/56c739923ada9683b699dc663073a9a8?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/56c739923ada9683b699dc663073a9a8?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Dark Reading","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Dark Reading","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/dr","url":"https://daily.dev/sources/dr"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/malicious-linux-implants-mimic-asian-mail-security-products-qrfnmbqg9","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,linux,malware","timeRequired":"PT6M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Dark Reading","item":"https://daily.dev/sources/dr"},{"@type":"ListItem","position":3,"name":"Malicious Linux Implants Mimic Asian Mail Security Products"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/malicious-linux-implants-mimic-asian-mail-security-products-qrfnmbqg9#faq","mainEntity":[{"@type":"Question","name":"How does BPFdoor hide its command-and-control traffic on compromised Linux systems?","acceptedAnswer":{"@type":"Answer","text":"BPFdoor stays dormant until it detects an activation code at a specific byte within incoming HTTPS requests, and it can propagate data to other internal machines by hiding codes inside ICMP pings. Newer variants also disguise themselves as South Korean anti-spam software SpamSniper, copying its process ID files and system services to blend in. Security teams tracking evolving backdoor techniques like these can follow research updates on daily.dev."}},{"@type":"Question","name":"Why do attackers use TCP port 25 for malware command-and-control instead of a custom port?","acceptedAnswer":{"@type":"Answer","text":"Port 25 is the standard SMTP port, so command-and-control traffic over it looks like ordinary email activity heading to a mail exchanger, making it hard to distinguish from normal enterprise mail flow. Malware like AVERAT and a modified Rekoobe RAT use this technique alongside typical SMTP handshake conventions before switching to an encrypted session. Teams hardening mail infrastructure against stealthy C2 channels can track findings like this on daily.dev."}},{"@type":"Question","name":"How can I detect a BPFdoor-style implant on a Linux secure email gateway?","acceptedAnswer":{"@type":"Answer","text":"Look for running processes whose executable file has been deleted, shown with a '(deleted)' suffix under /proc, since these implants delete their dropped files after launching. Also check for unexpected raw packet sockets, known dropper artifacts such as a /HDD/ms6x2xTo64/ directory, and monitor any outbound port 25 traffic from devices that are not mail services. Developers securing edge appliances against hidden implants can keep up with detection techniques via daily.dev."}}]}
```

