<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/smtp-is-the-key-bpfdoor-and-averat-hitting-the-network-edge-qtcqttgj6" -->

---
title: SMTP is the key: BPFDoor and AVERAT hitting the network edge
description: Rapid7 researchers detail a cluster of Linux malware targeting telecom and network-edge appliances, including a new BPFDoor variant, a BPF Rekoobe backdoor...
canonical: https://daily.dev/posts/smtp-is-the-key-bpfdoor-and-averat-hitting-the-network-edge-qtcqttgj6
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: SMTP is the key: BPFDoor and AVERAT hitting the network edge | daily.dev
og:description: Rapid7 researchers detail a cluster of Linux malware targeting telecom and network-edge appliances, including a new BPFDoor variant, a BPF Rekoobe backdoor...
og:url: https://daily.dev/posts/smtp-is-the-key-bpfdoor-and-averat-hitting-the-network-edge-qtcqttgj6
og:image: https://api.daily.dev/og/posts/qTcQTTGJ6.png
og:image:alt: SMTP is the key: BPFDoor and AVERAT hitting the network edge
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# SMTP is the key: BPFDoor and AVERAT hitting the network edge

**[Rapid7 Cybersecurity Blog](https://daily.dev/sources/rapid7-blog)** · 21 min read · 0 upvotes · 0 comments

## Summary

Rapid7 researchers detail a cluster of Linux malware targeting telecom and network-edge appliances, including a new BPFDoor variant, a BPF Rekoobe backdoor hitting South Korean SpamSniper anti-spam appliances, a dropper built for ShareTech devices, and six builds of a modular implant called AVERAT deployed against Taiwanese appliances. The samples disguise themselves with process names mimicking legitimate daemons and abuse SMTP (port 25) and HTTPS-wrapped magic packets to evade detection, since mail-security gateways and telecom appliances normally handle this traffic. Compromised consumer and SMB devices in Taiwan's Chunghwa Telecom HiNet space (NAS units, DVRs, an ADSL appliance) serve as relay infrastructure, with PPTP installed on all three for dual-purpose outbound C2 relay and inbound VPN access. The writeup also updates the Rapid7 BPFDoor controller's source code, documents AVERAT's RC4-encrypted configuration and command set, and provides detection guidance centered on fileless/unlinked process hunting, TLS fingerprinting, and staging-path indicators, plus full MITRE ATT&CK mappings and IOCs.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.rapid7.com/blog/post/tr-smtp-is-the-key-bpfdoor-averat-hitting-the-network-edge>

## Questions this post answers

### How does the new BPFDoor controller bypass deep packet inspection at the network edge?

It wraps the magic packet trigger inside a standard HTTPS POST request, such as POST /admin/login.aspx?id=99990, mathematically padded so the string '9999' lands at a fixed offset 26 in the TCP payload. This lets the backdoor locate its hex-encoded command payload after the HTTP headers even though proxies alter header lengths, evading static Layer 4 signatures built for older raw magic-byte detection.

_Tracking evasive C2 techniques like this helps defenders stay ahead; daily.dev surfaces threat research as it's published._

### Why would malware use TCP port 25 (SMTP) for command and control on a mail security appliance?

Outbound SMTP to arbitrary mail exchangers is the core legitimate function of a mail security gateway, so malicious traffic on port 25 is indistinguishable from normal operation in flow records. On SpamSniper appliances specifically, firewall rules permitting server-to-server relay on src/dst port 25 let a magic packet reach the raw socket before any stateful inspection occurs.

_Understanding why attackers pick protocols that blend with a device's normal job matters when hardening edge appliances like this._

### What indicates that a Linux process has been deleted from disk but is still running as malware?

Check /proc/<pid>/exe: if it resolves to a path suffixed with '(deleted)', the executable has been unlinked from disk while the process continues running in memory, leaving nothing on disk to hash, quarantine, or submit for analysis. Defenders should monitor process descriptors for this condition and inspect memory maps for executable pages lacking backing file paths.

_Fileless persistence tricks like this are worth tracking for anyone building Linux detection rules._

## Similar posts on daily.dev

- [China Upgrades the Backdoor It Uses to Spy on Telcos Globally](https://daily.dev/posts/china-upgrades-the-backdoor-it-uses-to-spy-on-telcos-globally-gm7orbujf) · Dark Reading · 0 upvotes · 0 comments
- [APT41 Delivers 'Undetectable' Backdoor to Steal Cloud Credentials](https://daily.dev/posts/apt41-delivers-undetectable-backdoor-to-steal-cloud-credentials-mvkzhqeh9) · Dark Reading · 0 upvotes · 0 comments
- [From bytecode to bytes: automated magic packet generation](https://daily.dev/posts/from-bytecode-to-bytes-automated-magic-packet-generation-ts88izwlt) · Cloudflare · 5 upvotes · 0 comments
- [DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors](https://daily.dev/posts/dprk-apts-ted-backdoor-and-curlrat-target-south-korean-media-and-automotive-sectors-amz4aeqgp) · Rapid7 Cybersecurity Blog · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#linux](https://daily.dev/tags/linux), [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/smtp-is-the-key-bpfdoor-and-averat-hitting-the-network-edge-qtcqttgj6)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"SMTP is the key: BPFDoor and AVERAT hitting the network edge","url":"https://daily.dev/posts/smtp-is-the-key-bpfdoor-and-averat-hitting-the-network-edge-qtcqttgj6","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/smtp-is-the-key-bpfdoor-and-averat-hitting-the-network-edge-qtcqttgj6"},"datePublished":"2026-10-02T13:20:11.047Z","dateModified":"2026-10-02T13:21:29.794Z","description":"Rapid7 researchers detail a cluster of Linux malware targeting telecom and network-edge appliances, including a new BPFDoor variant, a BPF Rekoobe backdoor...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/780f5b2a2f10df78d36a1e83cd10aaab?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/780f5b2a2f10df78d36a1e83cd10aaab?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Rapid7 Cybersecurity Blog","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Rapid7 Cybersecurity Blog","logo":"https://media.daily.dev/image/upload/logos/placeholder.jpg","url":"https://daily.dev/sources/rapid7-blog"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/smtp-is-the-key-bpfdoor-and-averat-hitting-the-network-edge-qtcqttgj6","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,linux,malware","timeRequired":"PT21M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Rapid7 Cybersecurity Blog","item":"https://daily.dev/sources/rapid7-blog"},{"@type":"ListItem","position":3,"name":"SMTP is the key: BPFDoor and AVERAT hitting the network edge"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/smtp-is-the-key-bpfdoor-and-averat-hitting-the-network-edge-qtcqttgj6#faq","mainEntity":[{"@type":"Question","name":"How does the new BPFDoor controller bypass deep packet inspection at the network edge?","acceptedAnswer":{"@type":"Answer","text":"It wraps the magic packet trigger inside a standard HTTPS POST request, such as POST /admin/login.aspx?id=99990, mathematically padded so the string '9999' lands at a fixed offset 26 in the TCP payload. This lets the backdoor locate its hex-encoded command payload after the HTTP headers even though proxies alter header lengths, evading static Layer 4 signatures built for older raw magic-byte detection. Tracking evasive C2 techniques like this helps defenders stay ahead; daily.dev surfaces threat research as it's published."}},{"@type":"Question","name":"Why would malware use TCP port 25 (SMTP) for command and control on a mail security appliance?","acceptedAnswer":{"@type":"Answer","text":"Outbound SMTP to arbitrary mail exchangers is the core legitimate function of a mail security gateway, so malicious traffic on port 25 is indistinguishable from normal operation in flow records. On SpamSniper appliances specifically, firewall rules permitting server-to-server relay on src/dst port 25 let a magic packet reach the raw socket before any stateful inspection occurs. Understanding why attackers pick protocols that blend with a device's normal job matters when hardening edge appliances like this."}},{"@type":"Question","name":"What indicates that a Linux process has been deleted from disk but is still running as malware?","acceptedAnswer":{"@type":"Answer","text":"Check /proc/<pid>/exe: if it resolves to a path suffixed with '(deleted)', the executable has been unlinked from disk while the process continues running in memory, leaving nothing on disk to hash, quarantine, or submit for analysis. Defenders should monitor process descriptors for this condition and inspect memory maps for executable pages lacking backing file paths. Fileless persistence tricks like this are worth tracking for anyone building Linux detection rules."}}]}
```

