Six builds of a previously undocumented Linux implant, a new BPFDoor variant and a Rekoobe-based backdoor all share one quiet trick: they talk over port 25, the mail port, on the very appliances whose job is to move mail. Rapid7 Intelligence's new report ties the samples to activity against South Korean systems and Taiwanese appliances, and names telecommunications and network-edge operators as the most affected.
The point is camouflage. A mail security gateway sends and receives SMTP all day, so command traffic dressed up as mail looks like the device doing its job.
An implant that says hello like a mail server
Rapid7 tracks the new implant as AVERAT, found in six builds deployed against Taiwanese appliances. It connects out on port 25, issues a normal EHLO greeting, asks for STARTTLS, and only then starts its own encrypted session over a hand-built TLS layer rather than a standard crypto library. It checks in roughly every ten minutes with basic host details. Its commands include file transfer, up to ten concurrent shells, loadable modules and a proxy channel through the device.
AVERAT arrives through a dropper that Rapid7 assesses was likely built for ShareTech appliances: it derives its encryption key from the string "ShareTech" and sits in the appliance's own add-on package directory. The dropper copies two binaries into /sbin as ntpdate and udevds, runs them, and deletes each file ten seconds later while the processes keep running. One of the two is the dropper itself, relaunched as a watchdog. A responder searching /sbin finds nothing to hash or quarantine.
Disguises cut to fit Korean anti-spam boxes
The BPFDoor samples seen against South Korean systems impersonate the PID file of SpamSniper, an anti-spam product used mainly in South Korea, and rotate through ten ordinary Linux daemon names. The Rekoobe-based backdoor waits for a trigger packet with both source and destination port set to 25, which Rapid7 notes would match a typical mail-relay firewall rule and reach the implant before stateful inspection.
Relays built from a NAS, a DVR and an old appliance
The three IP addresses in AVERAT's configurations belong to compromised third-party devices on Chunghwa Telecom's HiNet network in Taiwan: a Synology NAS owned by a fuel retailer, an obsolete NetKlass small-business appliance and a Dahua video recorder. All three expose an identical PPTP banner that Rapid7 assesses the operator installed, turning each into both a relay and a VPN foothold into its owner's network. Rapid7 says this matches the device profile that CISA, NCSC-UK and partner agencies described for China-nexus covert relay (ORB) networks in advisory AA26-113A, but it found no overlap with any named ORB network and says specific attribution remains an ongoing assessment. Telecom edge equipment has been a recurring espionage target, as in Salt Typhoon's European telecom intrusions, though Rapid7 draws no link between the two.
Hunt for deleted executables and odd port 25 traffic
Because nothing persists in /sbin, Rapid7 says file-based detection on the appliance is unlikely to work. Its guidance:
- Look for processes whose /proc/<pid>/exe target ends in "(deleted)", and for executable memory with no backing file on disk.
- Alert on the directory /HDD/ms6x2xTo64/, a .php file that starts with #!/bin/sh, a marker file named execProcEnd, and hidden .db state files.
- Flag a process tree of sh -c on a .php path, followed by cp and chmod into /sbin and an rm -rf of the same path within about ten seconds.
- Investigate raw packet sockets and classic BPF filters on systems that do not need packet capture, and outbound port 25 connections from processes that are not mail services.
Selected indicators
- Dropper (SHA-256): 2bedc26d4b29b435c21962beed7db21188a0219a0d28334bba8b4fb1656d7b15
- AVERAT (SHA-256): bf8135f46ecedfe5bd06fcecbb2e721c2367ff765b18f4aa3f868e6597f49e47
- BPFDoor, SpamSniper disguise (SHA-256): a37ea9897221d4495b538de72b74f2aa1d2ff09b7b6dcedd395aee58931adbf3
- AVERAT relay IPs (compromised victim devices): 59[.]125[.]211[.]65, 122[.]116[.]138[.]33, 1[.]34[.]200[.]85
The full hash list is in Rapid7's report. The uncomfortable lesson for defenders is that on a mail gateway, the most suspicious traffic and the most normal traffic can be the same protocol on the same port.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.