BPFDoor, BPF Rekoobe, and AVERAT Linux backdoor activity against telecom and network-edge appliances
Malware Activity
Summary
Hide ▲
Show ▼
BPFDoor, BPF Rekoobe, and AVERAT Linux backdoors were tracked against telecom and network-edge appliances in South Korea and Taiwan, raising the risk of stealthy compromise on devices that handle core communications traffic. The tooling hides by making sessions look like SMTP on TCP port 25 and by posing as legitimate services. It also adds deeper access features such as file transfer, shell sessions, and proxy/port-forwarding channels.
Related Happenings
Red Menshen telecom espionage campaign
Campaign
H score33
First: 26.03.2026 19:40
Last: 26.03.2026 19:40
Sources 1
About this happening:
A China-nexus Red Menshen operation has sustained covert access in telecom networks across the Middle East and Asia, increasing the risk of government espion...
Red Menshen telecom espionage campaign
CampaignAbout this happening: A China-nexus Red Menshen operation has sustained covert access in telecom networks across the Middle East and Asia, increasing the risk of government espion...
BPFDoor Linux backdoor with HTTPS-hidden trigger packets
Malware Activity
H score23
First: 26.03.2026 19:40
Last: 26.03.2026 19:40
Sources 1
About this happening:
A newly disclosed BPFDoor variant is hiding trigger packets inside HTTPS traffic and using ICMP between infected hosts, making the Linux backdoor harder to detect...
BPFDoor Linux backdoor with HTTPS-hidden trigger packets
Malware ActivityAbout this happening: A newly disclosed BPFDoor variant is hiding trigger packets inside HTTPS traffic and using ICMP between infected hosts, making the Linux backdoor harder to detect...
Timeline
-
02.10.2026 03:00 2 articles · 3d ago
Rapid7 identifies BPFDoor, BPF Rekoobe, and AVERAT on telecom and edge appliances
Initial DisclosureRapid7 identified a newly observed BPFDoor variant, a BPF Rekoobe build, and six AVERAT builds targeting telecom and network-edge appliances in South Korea and Taiwan. The tooling disguises traffic as SMTP on TCP port 25, sends EHLO and STARTTLS, imitates SpamSniper and other legitimate processes, and in AVERAT's case checks in every 600 to 699 seconds with file transfer, shell-session, and proxy or port-forwarding capability.
Show sources
- New Stealthy Linux Backdoors Target Telecoms, Masquerade as Email Traffic — www.infosecurity-magazine.com — 05.10.2026 17:00
- New Stealthy Linux Backdoors Target Telecoms, Masquerade as Email Traffic — www.infosecurity-magazine.com — 05.10.2026 17:00