Linux backdoors posing as email security tools quietly target servers in South Korea and Taiwan
Cyber firm Rapid7 says three Linux backdoors — BPFDoor, BPF Rekoobe, and AVERAT — are targeting systems in South Korea and Taiwan by impersonating trusted email security products and processes, with AVERAT even using standard email protocols for command‑and‑control.
A set of advanced backdoors aimed at Linux servers in South Korea and Taiwan is giving attackers long‑term access under the cover of routine email security software, according to new research.
Cybersecurity company Rapid7 reports that three malware families — BPFDoor, BPF Rekoobe, and AVERAT — have been found on Linux systems while disguising themselves as familiar email protection products or background processes. By copying the names and behavior of legitimate tools, the implants can run for extended periods without drawing attention.
The activity has been observed on networks in South Korea and Taiwan. Rapid7 has not publicly named specific victims, but says the backdoors are using tactics suited to high‑value environments where email servers and related infrastructure are central.
BPFDoor and BPF Rekoobe exploit how Linux handles low‑level packet filtering, listening for specially crafted network traffic that lets an outside operator reach a compromised server even through firewalls. AVERAT goes further by using SMTP, the standard protocol for email, as its command‑and‑control channel, so its traffic blends in with ordinary mail flows.
For administrators in South Korea and Taiwan, the findings mean that what appears to be a normal email security process could in fact be a remote‑control foothold. Because organizations are often reluctant to tightly restrict mail traffic, implants that hide there can be especially hard to root out.
National cyber agencies and major providers in both countries are now expected to issue technical guidance based on Rapid7’s work. How quickly those detection measures spread across hosting companies and large enterprises will determine whether the current campaigns are contained or continue to yield access for the operators behind BPFDoor, BPF Rekoobe, and AVERAT.
Sources
- OSINT