Skip to content

Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal. Detection, Dallas. Ava Okello: Report Finds Nearly Half of Deployed Detections Need Attention Before SOCs Can Trust Them.

SOCtember

Always First. Fast SOC News.

Rapid7 Labs investigation title card over a dark field.
Photo/figure: Rapid7 Labs research art, Sleeper Cells in the Telecom Backbone hero (fair use).

Threat Intel

Rapid7 Tracks BPFDoor and AVERAT Implants Mimicking Asian Mail Gateways

Rapid7 Intelligence published its first research drop on October 2, 2026, documenting Linux implants that impersonate South Korean SpamSniper and Taiwanese ShareTech mail-security appliances, with BPFDoor, Rekoobe, and a modular tool Rapid7 tracks as AVERAT blending command-and-control into SMTP traffic on the network edge.

Priya Shah, Threat IntelSingapore7 min read

SINGAPORE - Rapid7 Intelligence published its first research package on October 2, 2026, documenting Linux implants that borrow the filenames, process conventions, and traffic profiles of Asian secure email gateways rather than advertising themselves as malware. The release accompanies the launch of Rapid7 Intelligence, a unified engine that folds threat intelligence, vulnerability research, and Rapid7 Labs work into the company's products and managed detection and response service. The operational finding for security operations teams is sharper than a product announcement: two overlapping campaigns are treating mail-security appliances as long-term footholds on the path between the internet and the core.

In the South Korean cluster, Rapid7 describes BPFDoor variants and a BPF-enabled Rekoobe build that impersonate SpamSniper, an anti-spam product used across thousands of organizations in the Asia-Pacific region. Samples rotate through common Linux daemon names, reuse SpamSniper-style PID files, and attach classic Berkeley Packet Filter programs that wait for a magic packet before opening interactive access. One data-plane sample spoofs process names that would look ordinary on Oracle-backed telecom subscriber and provisioning hosts. Rekoobe builds sniff traffic with source and destination ports set to 25, matching the SMTP relay profile defenders expect on a mail gateway and the firewall rules that usually allow it.

C source comparing classic and extended BPFDoor magic packet structures.
Photo/figure: Rapid7 Labs, New magic packet structure from BPFDoor variant research (fair use).A longer magic-packet layout adds a hidden next-hop address.
Diagram of a two-hop ICMP relay from an initial server through an infected BPFDoor gateway.
Photo/figure: Rapid7 Labs, ICMP relay using the HIP (Hidden IP) field (fair use).The hidden IP field is used to relay a magic packet inward.

The Taiwanese cluster centers on a local dropper keyed to the string ShareTech and a modular implant Rapid7 tracks as AVERAT. The dropper writes a shell script under a .php extension on the appliance storage mount, copies payloads into /sbin as ntpdate and udevds, launches them, and deletes the on-disk copies about ten seconds later while the processes keep running. From that point, /proc/*/exe resolves to a deleted path, so hash-based quarantine has little to scan. AVERAT then dials outbound TCP port 25, speaks EHLO and STARTTLS like a mail exchanger, and only afterward starts its own encrypted session. Check-ins report hostname, user, operating system, interfaces, and logged-in users on an interval that Rapid7 measured between 600 and 699 seconds and that operators can change through a hidden state file.

Command-and-control infrastructure recovered from AVERAT configs sat on compromised consumer and small-business gear in Chunghwa Telecom's HiNet space rather than on dedicated attacker hosts: a Synology NAS, an obsolete NetKlass edge appliance, and a Dahua digital video recorder, each reachable, unpatched, and unlikely to be audited. Rapid7 assesses the pattern as consistent with the broader operational-relay-box device class described in joint government guidance on China-nexus covert networks, while stopping short of tying the campaign to a named ORB cluster. Dark Reading, amplifying the research on the same day, quoted Christiaan Beek, vice president of Rapid7 Intelligence, on why secure email gateways make attractive targets. "These devices sit at the network edge, on the path between the Internet and the core, and are often trusted by the firewall rules around them," Beek said. "A foothold there is well placed for long-term access, particularly in telecom environments."

Chart of a telecom network from customer edge services through the core to control-plane databases.
Photo/figure: Rapid7 Labs chart, Telecom provider network diagram (fair use).Mail and security appliances sit on the path between the edge and the core.
Configuration notes listing a command-and-control address, port, URI, and cookie beacon.
Photo/figure: Rapid7 Labs chart, Cross-C2 configuration from telecom research (fair use).Command-and-control parameters recovered in the research.

Detection guidance from Rapid7 is host-first because file-based scans on the appliance rarely find a payload that no longer exists in /sbin. Hunt for processes whose executable has been unlinked, unexpected raw packet sockets and classic BPF filters on Linux systems that do not need packet capture, dropper artifacts under /HDD/ms6x2xTo64/, and outbound TCP port 25 from processes that are not mail services. Beek told Dark Reading that many organizations also lack a baseline of normal outbound mail traffic from their appliances, which is exactly what makes SMTP-shaped command-and-control hard to spot. Restricting management access to routers, DVRs, and other edge devices, and watching NFS or SMB mounts that could let an adjacent host write executables onto an embedded appliance, round out the defensive list.

This wire is distinct from the live Citrix NetScaler disclosure, from LevelBlue's Citrix post-exploitation hunt pack, from Huntress Tragic Quadrant RMM telemetry, and from Binary Defense's Microsoft 365 encryptionless extortion staging. The news here is Rapid7's October 2 mapping of SpamSniper- and ShareTech-mimicking edge implants and the SMTP blending that keeps them under mail-gateway noise.

Sources:


Priya Shah covers threat intelligence and adversary tradecraft for SOCtember from Singapore.

Related stories

Threat Intel desk