
Rapid7 Tracks BPFDoor and AVERAT Implants Mimicking Asian Mail Gateways
Rapid7 Intelligence published its first research drop on October 2, 2026, documenting Linux implants that impersonate South Korean SpamSniper and Taiwanese ShareTech mail-security appliances, with BPFDoor, Rekoobe, and a modular tool Rapid7 tracks as AVERAT blending command-and-control into SMTP traffic on the network edge.
Priya Shah, Threat IntelSingapore7 min read
SINGAPORE - Rapid7 Intelligence published its first research package on October 2, 2026, documenting Linux implants that borrow the filenames, process conventions, and traffic profiles of Asian secure email gateways rather than advertising themselves as malware. The release accompanies the launch of Rapid7 Intelligence, a unified engine that folds threat intelligence, vulnerability research, and Rapid7 Labs work into the company's products and managed detection and response service. The operational finding for security operations teams is sharper than a product announcement: two overlapping campaigns are treating mail-security appliances as long-term footholds on the path between the internet and the core.
In the South Korean cluster, Rapid7 describes BPFDoor variants and a BPF-enabled Rekoobe build that impersonate SpamSniper, an anti-spam product used across thousands of organizations in the Asia-Pacific region. Samples rotate through common Linux daemon names, reuse SpamSniper-style PID files, and attach classic Berkeley Packet Filter programs that wait for a magic packet before opening interactive access. One data-plane sample spoofs process names that would look ordinary on Oracle-backed telecom subscriber and provisioning hosts. Rekoobe builds sniff traffic with source and destination ports set to 25, matching the SMTP relay profile defenders expect on a mail gateway and the firewall rules that usually allow it.


The Taiwanese cluster centers on a local dropper keyed to the string ShareTech and a modular implant Rapid7 tracks as AVERAT. The dropper writes a shell script under a .php extension on the appliance storage mount, copies payloads into /sbin as ntpdate and udevds, launches them, and deletes the on-disk copies about ten seconds later while the processes keep running. From that point, /proc/*/exe resolves to a deleted path, so hash-based quarantine has little to scan. AVERAT then dials outbound TCP port 25, speaks EHLO and STARTTLS like a mail exchanger, and only afterward starts its own encrypted session. Check-ins report hostname, user, operating system, interfaces, and logged-in users on an interval that Rapid7 measured between 600 and 699 seconds and that operators can change through a hidden state file.
Command-and-control infrastructure recovered from AVERAT configs sat on compromised consumer and small-business gear in Chunghwa Telecom's HiNet space rather than on dedicated attacker hosts: a Synology NAS, an obsolete NetKlass edge appliance, and a Dahua digital video recorder, each reachable, unpatched, and unlikely to be audited. Rapid7 assesses the pattern as consistent with the broader operational-relay-box device class described in joint government guidance on China-nexus covert networks, while stopping short of tying the campaign to a named ORB cluster. Dark Reading, amplifying the research on the same day, quoted Christiaan Beek, vice president of Rapid7 Intelligence, on why secure email gateways make attractive targets. "These devices sit at the network edge, on the path between the Internet and the core, and are often trusted by the firewall rules around them," Beek said. "A foothold there is well placed for long-term access, particularly in telecom environments."


Detection guidance from Rapid7 is host-first because file-based scans on the appliance rarely find a payload that no longer exists in /sbin. Hunt for processes whose executable has been unlinked, unexpected raw packet sockets and classic BPF filters on Linux systems that do not need packet capture, dropper artifacts under /HDD/ms6x2xTo64/, and outbound TCP port 25 from processes that are not mail services. Beek told Dark Reading that many organizations also lack a baseline of normal outbound mail traffic from their appliances, which is exactly what makes SMTP-shaped command-and-control hard to spot. Restricting management access to routers, DVRs, and other edge devices, and watching NFS or SMB mounts that could let an adjacent host write executables onto an embedded appliance, round out the defensive list.
This wire is distinct from the live Citrix NetScaler disclosure, from LevelBlue's Citrix post-exploitation hunt pack, from Huntress Tragic Quadrant RMM telemetry, and from Binary Defense's Microsoft 365 encryptionless extortion staging. The news here is Rapid7's October 2 mapping of SpamSniper- and ShareTech-mimicking edge implants and the SMTP blending that keeps them under mail-gateway noise.
Sources:
- Rapid7: Rapid7 Launches Rapid7 Intelligence to Harness Threat Data Against Attackers, Oct 2, 2026
- Dark Reading: Malicious Linux Implants Mimic Asian Mail Security Products (Nate Nelson, Dark Reading, Oct 2, 2026)
- Security Intel Hub: SMTP is the key: BPFDoor and AVERAT hitting the network edge, Oct 2, 2026
- Rapid7: New Whitepaper: Stealthy BPFDoor Variants are a Needle That Looks Like Hay (Rapid7 Labs, Apr 2, 2026)
Priya Shah covers threat intelligence and adversary tradecraft for SOCtember from Singapore.
Related stories
Response
Citrix Confirms Two NetScaler RCE Zero-Days Exploited in the Wild
Detection
Microsoft Tracks EvilTokens Phishing Kit Behind Device Code Token Theft
Threat Intel
Mandiant Warns ShinyHunters Bypass WAFs to Resume PeopleSoft Mass Exploitation
Response