New AVERAT Linux implant hides command traffic inside SMTP on telecom edge devices

Rapid7 documented a new modular Linux implant called AVERAT alongside fresh BPFDoor variants, both abusing TCP port 25 to blend command-and-control traffic into ordinary mail flows.

New AVERAT Linux implant hides command traffic inside SMTP on telecom edge devices

At a glance

  • AVERAT beacons over SMTP on TCP port 25 every 600 to 699 seconds and supports shells, file transfer, proxying and module loading
  • Six AVERAT builds impersonate Taiwanese vendor ShareTech's mail security appliances; related BPFDoor and Rekoobe variants masquerade as South Korean anti-spam product SpamSniper
  • Operators relayed traffic through three compromised Taiwanese consumer devices, including a Synology NAS and a Dahua DVR
  • Rapid7 found no overlap with any named ORB network and does not attribute the activity to a specific threat actor

Rapid7 published research on October 2 describing a previously undocumented modular Linux implant it tracks as AVERAT, found alongside new variants of the BPFDoor backdoor on telecom and network-edge systems in Taiwan and South Korea. According to Rapid7, both malware sets share one defining trick: they route command-and-control traffic over TCP port 25, the standard SMTP port, so that implant communications look like routine mail server activity inside the victim's DMZ.

What happened

Rapid7 says it tracked a cluster of Linux samples that deliberately blend into the software and device conventions of the environments they target. The set includes a new BPFDoor variant, a BPF Rekoobe build seen against South Korean targets, a dropper, and six builds of the AVERAT implant deployed against Taiwanese appliances. The six AVERAT builds share identical MAC and auxiliary cryptographic keys, which is how Rapid7 grouped them.

The disguises are specific. According to Rapid7, the South Korean cluster masquerades as SpamSniper, a Korean anti-spam product, including PID spoofing and a /var/run/spamsniper.pid artifact, while the dropper associated with AVERAT derives its encryption key from the string ShareTech, the name of a Taiwanese mail security appliance vendor. Rapid7 reads this as a sign the operators knew their target environments well. Other samples impersonated Oracle-based telecom platform processes such as ora_ppmond.

Technical details

Rapid7 reports that AVERAT beacons out over port 25 every 600 to 699 seconds, reporting the hostname, current user, OS version, network interfaces and logged-in users. Its capabilities include directory enumeration and recursive file operations, process enumeration and termination, file upload and download with resume support, up to ten concurrent interactive shells, dynamic reconfiguration of the C2 host and port, loading of shared-object modules, port forwarding and proxy channels, and a reboot command. Configuration lives in a 276-byte encrypted blob using an RC4-derived keystream.

The BPFDoor side relies on Berkeley Packet Filters to watch traffic passively without opening a listening port. Rapid7 notes that where older variants waited for raw magic byte values such as 0x7255 and 0x5293, the newer controller sends benign-looking web requests, for example POST /admin/login.aspx?id=99990, padded so a reference string lands at a fixed offset in the TCP payload; the backdoor uses that offset to locate and decode a hex-encoded command. A Rekoobe variant was seen filtering specifically for traffic with both source and destination port 25, which survives the firewall rules mail servers already allow.

For relaying, Rapid7 identified three compromised customer-premises devices in Chunghwa Telecom's HiNet address space: a Synology NAS belonging to a Taiwanese fuel-retail business, an SMB ADSL/FTTH network appliance, and a Dahua DH-XVR5116HS-I3 recorder. All three also exposed PPTP on port 1723 with an identical banner, which Rapid7 reads as an operator-installed VPN foothold.

Attribution and who is affected

Rapid7 does not name a threat actor. It notes the infrastructure pattern is consistent with the China-nexus covert relay networks described in the April 2026 CISA and NCSC-UK joint advisory AA26-113A, but states it found no infrastructure or indicator overlap with any specific named ORB network, and that attribution remains an ongoing assessment. Affected parties so far are telecommunications operators, mail security gateways, network-edge and SMB appliances, and embedded CCTV and DVR systems.

What to do

Rapid7's detection guidance focuses on host and traffic anomalies rather than file hashes. Defenders should hunt for Linux processes whose executable has been unlinked, where /proc/<pid>/exe shows a (deleted) suffix, look for hidden state files such as /var/lib/.db, and alert on raw packet sockets and classic BPF filters on systems that have no packet-capture role. On the network side, Rapid7 recommends reviewing outbound port 25 traffic from appliances that are not mail servers, and in particular mail-role hostnames that resolve to consumer-grade or embedded devices. It also advises restricting management access to routers, DVRs and other edge appliances, and preserving process memory, open file descriptors and historical DNS records during investigations, because staged binaries are short-lived.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.