HomeSecurityLinux backdoors Mimic Email Security Tools to Avoid Detection in...

Linux backdoors mimic email security tools to evade detection in Korea and Taiwan

Linux backdoors targeting telecommunications and networking devices in South Korea and Taiwan have disguised their traffic as email services and seemingly legitimate processes to integrate and evade detection.

See also: React2Shell vulnerability used to install Linux Backdoors

Article image: Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan
Linux backdoors mimic email security tools to evade detection in Korea and Taiwan

Malicious actors often name their malware with names that refer to legitimate operating system components or processes as a measure to avoid detection. By borrowing the name of a real binary file, it can appear less prominent among other processes, give it a false sense of trust, or be overlooked by an analyst during a casual inspection.

However, the backdoors examined by Rapid7 have been found to go beyond just spoofing filenames, impersonating email security products such as SpamSniper and ShareTech, which are widely used in corporate environments in South Korea and Taiwan. According to vendor Jiran Group, SpamSniper is advertised as “Korea’s leading email security solution” that protects organizations from spam, malware, and server attacks.

The malicious artifacts include a new BPFDoor and a BPF Rekoobe used against targets in South Korea, as well as a previously unreported Linux implant called AVERAT delivered via a dropper and deployed against devices in Taiwan.

“The BPFDoor variants observed against South Korean systems impersonate the PID file of SpamSniper, a Korean anti-spam product, and switch between ten Linux daemon names,” Rapid7 reported. “In all samples, each component adopts names and conventions designed to appear trivial in the targeted environment.”

BPFdoor and its many variants were the subject of extensive analysis by Rapid7 earlier this year, with activity linked to a threat group called Red Menshen (also known as Earth Bluecrow, DecisiveArchitect, and Red Dev 18), which has targeted telecommunications providers across the Middle East and Asia since 2021.

See also: Linux PAM abused to create backdoors

Linux backdoors - SecNews.gr
Linux backdoors mimic email security tools to evade detection in Korea and Taiwan

At a high level, BPFDoor leverages the functionality of the Berkeley Packet Filter (BPF) to inspect incoming network traffic and only activate its behavior when it detects a magic packet. The detection of a new version of BPFDoor suggests that the threat actors behind the malware are actively improving and rebuilding their arsenal in response to public revelations.

“Once security vendors wrote static network signatures (Suricata/Snort) to detect these Layer 4 anomalies, operators began targeting edge proxies,” Rapid7 reported. “By wrapping the magic packet in standard HTTPS POST requests and relying on SSL offloading common in telecommunications environments, the stimulus can be delivered to the infected BPFDoor node in a way that can evade conventional deep packet inspection.”

While some BPFDoor samples mimic SpamSniper, another artifact sets its process name to “ora_ppmond,” mimicking the naming convention associated with Oracle-supported subscriber and telecommunications platforms. Specifically, the name appears to refer to “ora_pmon_*,” which represents the Process Monitoring (PMON) process of an Oracle database instance.

Once activated, the BPFDoor sample starts a TinyShell session and supports commands to facilitate an interactive shell, upload and download capabilities. Interestingly, the use of TinyShell has previously been attributed to Chinese groups such as Liminal Panda, UNC3886 (aka Fire Ant) , and Velvet Ant, all of which have targeted telecommunications networks and edge devices.

“These samples show BPFDoor operating as a modular framework that adapts to the targeted telecommunications layer, integrating TinyShell and Rekoobe logic to support data extraction,” Rapid7 explained.

Additionally, a Rekoobe-based BPF backdoor was observed in conjunction with the activity that intercepts TCP/UDP/SCTP IPv4 and UDP IPv6 with equal source and destination ports of 25. Furthermore, it names its processes after elements of SpamSniper.

See also: Linux ClingSTUN turns vulnerable IoT devices into proxy nodes

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Claude Mythos 5 AI model malware dropper open-source attack
Linux backdoors mimic email security tools to evade detection in Korea and Taiwan

The dropper observed in an overlapping campaign is an ELF binary that acts as a local installer for AVERAT, a modular implant that uses the Simple Message Transfer Protocol (SMTP).

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS