HomeRisk ManagementsLinux Backdoors Target Telecoms and Disguise as Email Traffic

Linux Backdoors Target Telecoms and Disguise as Email Traffic

Published on

spot_img

Cybersecurity Alert: Linux Backdoors Disguise Malicious Activity in Telecom Devices across South Korea and Taiwan

Emerging cybersecurity threats have been identified targeting telecom and network-edge devices in South Korea and Taiwan. Recent findings highlight a sophisticated approach where backdoors are employed to disguise malicious traffic as routine email communications while masking the unauthorized processes as legitimate services. Such tactics pose considerable risks to both national security and corporate infrastructures within these regions.

In a detailed research report published on October 2 by Rapid7, a cybersecurity firm, analysts tracked a recently identified variant of BPFDoor alongside the BPF Rekoobe build, both of which were employed specifically against South Korean targets. Furthermore, the study detailed the deployment of a dropper and six versions of an implant referred to as AVERAT, which were found infiltrating Taiwanese devices. The implications of this research underscore the need for heightened vigilance against such cyber threats.

The AVERAT implant operates by establishing connections over Transmission Control Protocol (TCP) port 25, utilizing the Simple Mail Transfer Protocol (SMTP) to initiate communications. The implant begins its operations by sending an email command (EHLO) and requesting STARTTLS to commence an encrypted session. This methodology allows it to effectively blend in with normal network traffic on mail security gateways, making its presence virtually indistinguishable from legitimate email activities. Rapid7 pointed out that this capability poses significant challenges for cybersecurity monitoring efforts, as legitimate outbound mail traffic forms the core function of devices in these environments.

The frequency of the implant’s check-ins is suspiciously regular, occurring every 600 to 699 seconds. Its arsenal of commands is broad, including provisions for file transfers, process terminations, and the ability to manage up to ten concurrent shell sessions, as well as establishing proxy or port-forwarding channels. Such extensive operational capabilities reveal the potential threat levels posed by these malicious implants.

Hiding in Plain Sight: Port 25 as a Backdoor

The BPF Rekoobe variant specifically monitors traffic originating from and directed towards port 25, cleverly naming its associated processes after components of SpamSniper—a widely used anti-spam solution in South Korea. This clever mimicry allows the malware to evade detection since firewall rules designed to enable mail relay between servers may permit the implant to receive trigger packets before traditional stateful inspections can identify and intercept the threat.

Similarly, the South Korean variant of BPFDoor also assumes the identity of SpamSniper, while another version chooses names associated with processes found on Oracle-based telecom subscriber platforms. Rapid7 further examined a BPFDoor controller that wraps its trigger within HTTPS POST requests, thus enabling the potential to bypass edge proxies and conventional deep-packet inspection techniques.

As cybersecurity experts continue to analyze the breadth of these threats, related concerns have arisen regarding the use of hijacked devices as relays for malicious operations. The AVERAT variants connect to hardcoded addresses located on compromised third-party devices in Taiwan, including familiar devices such as Synology NAS units, outdated small-business appliances, and Dahua video recorders. Notably, all three targeted devices were found to run identical PPTP VPN services, which are believed to have been installed by the threat operators to create backdoor access into the networks of their victims.

Rapid7 highlighted that these relays align with device profiles mentioned in a notable advisory released in April by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and its partners, which addressed covert networks attributed to China, commonly known as operational relay box (ORB) networks. However, the report indicated no overlap with any identified ORB networks, and ongoing attribution efforts are still in progress.

Recommendations for Mitigation

In light of these findings, Rapid7 has urged organizations to take proactive measures against this growing threat. Recommendations include a thorough investigation of unexpected raw packet sockets and BPF filters, closely watching outbound connections on port 25 that originate from non-mail services, and scrutinizing any processes masquerading as common daemons. Additionally, restricting management access to routers, Digital Video Recorders (DVRs), and other edge appliances is advised as a means to bolster defense against such covert cyber intrusions.

As cybersecurity threats evolve, the need for a robust and adaptive defense strategy becomes increasingly paramount. Organizations in South Korea and Taiwan, along with international partners, must remain vigilant and responsive to safeguard their infrastructure against these sophisticated cyber espionage tactics. The battle against such cyber adversaries is ongoing, and a collective effort among businesses, governments, and cybersecurity professionals will be vital in securing these critical systems.

Source link

Latest articles

New RemoveMacAI Tool Eliminates Apple Intelligence Models and Frees Up Mac Storage

New Open-Source Utility Removes Apple Intelligence Features from macOS A groundbreaking command-line utility named RemoveMacAI...

Q&A with Oliver Simonnet at CultureAI: AI Security in 2026 – Organizations’ Reliance on AI and the Path Forward

In recent years, artificial intelligence (AI) has transitioned from a niche technology, predominantly understood...

ClingSTUN Malware Converts Unpatched IoT Devices into Proxy Nodes

Title: The Emergence of ClingSTUN: A New Cyber Threat Targeting IoT Devices In recent cybersecurity...

Key ShinyHunters Suspect Detained in Jordan

Saif al-Din Khader’s Detention Highlights Ongoing Cybercrime Challenges The cybersecurity landscape is facing significant upheaval...

More like this

New RemoveMacAI Tool Eliminates Apple Intelligence Models and Frees Up Mac Storage

New Open-Source Utility Removes Apple Intelligence Features from macOS A groundbreaking command-line utility named RemoveMacAI...

Q&A with Oliver Simonnet at CultureAI: AI Security in 2026 – Organizations’ Reliance on AI and the Path Forward

In recent years, artificial intelligence (AI) has transitioned from a niche technology, predominantly understood...

ClingSTUN Malware Converts Unpatched IoT Devices into Proxy Nodes

Title: The Emergence of ClingSTUN: A New Cyber Threat Targeting IoT Devices In recent cybersecurity...