Sophisticated malware developers are creating Linux implants that closely mimic Korean and Taiwanese network edge appliances, making them exceptionally difficult to detect. These advanced backdoors go beyond superficial imitation by replicating filenames, firewall-allowed traffic, and the specific operational habits of the popular email security devices they infect, as first reported by Dark Reading.
Researchers have identified two overlapping campaigns utilizing these sophisticated implants. One campaign involves new variants of the BPFdoor backdoor and the Rekoobe remote access Trojan (RAT), which have been observed mimicking South Korean anti-spam software 'SpamSniper' and disguising themselves as legitimate background processes. The other campaign centers around a novel tool called AVERAT, which targets Taiwanese mail security vendor ShareTech Information appliances. Both BPFdoor and AVERAT leverage Transmission Control Protocol (TCP) Port 25, the standard for Simple Mail Transfer Protocol (SMTP), to blend command-and-control (C2) traffic with normal email communications. This strategy exploits the privileged position of secure email gateways (SEGs) at the network edge, their closed nature limiting endpoint detection, and the difficulty in establishing a baseline for normal outbound mail traffic, making detection challenging.
Source: Dark Reading
