Rapid7: BPFDoor and AVERAT implants hide on mail appliances behind port 25
Rapid7 has published an analysis of a set of Linux implants aimed at telecom operators and other organisations at the network edge, with samples seen against systems in South Korea and Taiwan. The report, dated 2 October, covers a new variant of the long-running BPFDoor backdoor, a build of the Rekoobe backdoor, a dropper, and six builds of an implant Rapid7 tracks as AVERAT. Rapid7 also describes new features of a BPFDoor controller whose source code it reconstructed.
The common thread is disguise fitted to the target. In the Taiwanese chain, a dropper writes a shell script, given a .php extension, to the appliance's storage. The script copies two payloads into /sbin under the names ntpdate and udevds, starts them, and deletes the files about ten seconds later while the processes keep running. One of the payloads is the dropper itself, acting as a watchdog, so nothing malicious remains on disk in /sbin. In South Korea, the BPFDoor samples imitate the PID file of SpamSniper, a Korean anti-spam product, and rotate through ten ordinary Linux daemon names. Both campaigns sit on mail-security appliances placed in front of a mail server, which gives an implant there a view of an organisation's inbound and outbound mail, and both use port 25 so that their traffic looks like the SMTP the device is supposed to carry.
The trigger has moved inside HTTPS. Older BPFDoor builds waited for "magic bytes" in raw TCP or UDP headers, which network signatures learned to spot. According to Rapid7, the newer controller wraps the trigger in ordinary-looking web requests that pass through the TLS termination common in telecom networks. Because proxies rewrite headers, the request is padded so that a marker always falls at the same position in the payload. Rapid7 found no infrastructure overlap with any named network of compromised relay devices and says attribution remains an ongoing assessment.
What to look for. Rapid7 says file-based scanning of the appliance is unlikely to work. Instead it recommends looking for processes whose executable has been unlinked — on Linux, a /proc/<pid>/exe target ending in (deleted) — and for executable memory pages with no backing file; a process tree in which sh -c runs a .php path, then cp and chmod into /sbin, then rm -rf of the same path within about ten seconds; raw packet sockets and classic BPF filters on systems that have no reason to capture packets; and outbound port-25 connections from processes that are not mail services. Management access to routers, DVRs and similar appliances should be restricted.

Why it matters
Security appliances are often the least inspected machines on a network: closed systems, vendor-managed, rarely patched. These samples are built for exactly that blind spot. Teams that own such boxes should ask whether they can see process and socket state on them at all — because the indicators Rapid7 lists live there, not in files.