Back to Newsroom
Threat Intel

Linux Backdoors Pose as Email Security Software to Hit Telecoms in Korea and Taiwan

A cluster of Linux backdoors is disguising itself as trusted email-security and telecom software to stay hidden inside compromised network appliances across South Korea and Taiwan.

Linux Backdoors Pose as Email Security Software to Hit Telecoms in Korea and Taiwan

A wave of Linux malware is quietly working its way into telecom and network appliances across South Korea and Taiwan by hiding in plain sight — impersonating the very email-security software these organizations rely on to stay safe.

What happened

Security researchers tracking the activity found that the malware goes well beyond the usual trick of copying a legitimate file name. Several components actively assume the identity of real, widely deployed email-security products used across South Korean and Taiwanese enterprises, mimicking their process names and conventions closely enough to blend into normal system activity.

The cluster includes a new variant of BPFDoor, a stealthy passive backdoor that abuses the Linux kernel's packet-filtering layer to silently watch network traffic and only "wake up" when it spots a specially crafted trigger packet — no open ports, no obvious listener, nothing a routine port scan would catch. This latest version goes further: it can deliver that wake-up trigger disguised as ordinary encrypted web traffic, making it harder for standard deep-packet-inspection tools to flag.

Alongside it, researchers identified a backdoor built on the Rekoobe toolkit that specifically watches mail-related ports, and a previously undocumented implant, tracked as AVERAT, deployed against Taiwanese targets. AVERAT is delivered through a small installer hidden inside a legitimate-looking add-on folder of a mail-security appliance, which decrypts and runs its payload before deleting the installation traces within seconds. Once active, it checks in with its control server over the mail-transfer port on a staggered schedule and supports a wide command set — file transfer, directory enumeration, process control, proxying traffic through the infected device, and even rebooting the appliance.

Why it matters

Email security gateways and telecom edge appliances sit in a privileged spot: they see a constant stream of sensitive traffic and are often trusted, lightly monitored, and rarely rebooted. Backdoors that pose as the very security software protecting that traffic are built to survive routine checks and to blend into noise defenders already expect to see. The command and control channels here lean on protocols — standard web traffic, mail ports — that security teams are least likely to flag as suspicious, which is what makes this kind of regionally tailored, protocol-blending malware so durable once it gets a foothold.

What to do

  • Review Linux hosts and appliances for unexpected raw packet sockets or BPF filter usage outside of legitimate packet-capture tools.
  • Audit outbound connections on mail-related ports from any process that isn't your actual mail server or gateway software.
  • Treat process names alone as unreliable — verify that processes claiming to be your security or monitoring software match expected binaries, hashes, and install paths.
  • Tighten and monitor management access to routers, mail gateways, DVRs, and other edge devices, which are increasingly used as long-term footholds rather than just entry points.
  • Keep email security gateways and similar appliances patched and treat them as high-value targets in your monitoring strategy, not just as security tooling.
SHARE