Endpoint/Device Security, Malware, Threat Intelligence

New Linux malware mimics network edge appliances to evade detection

Closeup of a mobile phone screen with logo lettering of linux on computer keyboard

Sophisticated malware developers are creating Linux implants that closely mimic Korean and Taiwanese network edge appliances, making them exceptionally difficult to detect. These advanced backdoors go beyond superficial imitation by replicating filenames, firewall-allowed traffic, and the specific operational habits of the popular email security devices they infect, as first reported by Dark Reading.

Researchers have identified two overlapping campaigns utilizing these sophisticated implants. One campaign involves new variants of the BPFdoor backdoor and the Rekoobe remote access Trojan (RAT), which have been observed mimicking South Korean anti-spam software 'SpamSniper' and disguising themselves as legitimate background processes. The other campaign centers around a novel tool called AVERAT, which targets Taiwanese mail security vendor ShareTech Information appliances. Both BPFdoor and AVERAT leverage Transmission Control Protocol (TCP) Port 25, the standard for Simple Mail Transfer Protocol (SMTP), to blend command-and-control (C2) traffic with normal email communications. This strategy exploits the privileged position of secure email gateways (SEGs) at the network edge, their closed nature limiting endpoint detection, and the difficulty in establishing a baseline for normal outbound mail traffic, making detection challenging.

Source: Dark Reading

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds