Find notable cyber news and cases, enriched with sources, timelines, and signals.

BPFDoor, BPF Rekoobe, and AVERAT Linux backdoor activity against telecom and network-edge appliances

Malware Activity
First reported
Last updated
Happening score
H score 22
1 unique sources, 1 articles

Summary

Hide ▲

BPFDoor, BPF Rekoobe, and AVERAT Linux backdoors were tracked against telecom and network-edge appliances in South Korea and Taiwan, raising the risk of stealthy compromise on devices that handle core communications traffic. The tooling hides by making sessions look like SMTP on TCP port 25 and by posing as legitimate services. It also adds deeper access features such as file transfer, shell sessions, and proxy/port-forwarding channels.

Related Happenings

Red Menshen telecom espionage campaign

Campaign
H score33 First: 26.03.2026 19:40 Last: 26.03.2026 19:40 Sources 1

About this happening: A China-nexus Red Menshen operation has sustained covert access in telecom networks across the Middle East and Asia, increasing the risk of government espion...

BPFDoor Linux backdoor with HTTPS-hidden trigger packets

Malware Activity
H score23 First: 26.03.2026 19:40 Last: 26.03.2026 19:40 Sources 1

About this happening: A newly disclosed BPFDoor variant is hiding trigger packets inside HTTPS traffic and using ICMP between infected hosts, making the Linux backdoor harder to detect...

Timeline

  1. 02.10.2026 03:00 2 articles · 3d ago

    Rapid7 identifies BPFDoor, BPF Rekoobe, and AVERAT on telecom and edge appliances

    Initial Disclosure

    Rapid7 identified a newly observed BPFDoor variant, a BPF Rekoobe build, and six AVERAT builds targeting telecom and network-edge appliances in South Korea and Taiwan. The tooling disguises traffic as SMTP on TCP port 25, sends EHLO and STARTTLS, imitates SpamSniper and other legitimate processes, and in AVERAT's case checks in every 600 to 699 seconds with file transfer, shell-session, and proxy or port-forwarding capability.

    Show sources