Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Linux Backdoors Mimic Email Tools to Evade Detection

Linux Backdoors Mimic Email Tools to Evade Detection

Posted on October 6, 2026 By CWS

Linux backdoors are posing a significant threat to telecom and network devices in South Korea and Taiwan. These backdoors are cleverly camouflaging themselves as email security tools to slip past detection mechanisms.

Impersonation Tactics of Threat Actors

Threat actors often use the names of legitimate system components to disguise malicious software. By adopting such names, they aim to make their software appear trustworthy or inconspicuous among legitimate processes. However, recent analyses by Rapid7 reveal that some backdoors are not just mimicking file names but are also posing as well-known email security solutions like SpamSniper and ShareTech, commonly used in South Korean and Taiwanese enterprises.

SpamSniper, as promoted by Jiran Group, is a leading email security tool in Korea, designed to shield organizations from spam, malware, and server threats. The backdoors exploit these trusted names to enhance their stealth capabilities.

Advanced Techniques and Variants

Among the newly identified threats are a BPFDoor variant and a BPF Rekoobe build targeting South Korean systems, alongside the AVERAT implant targeting Taiwanese devices. These backdoors adopt names of legitimate processes, such as those associated with anti-spam products, to avoid detection. Rapid7’s investigation links these activities to a threat group known as Red Menshen, active since 2021.

BPFDoor leverages Berkeley Packet Filter (BPF) functionality to monitor network traffic, activating only in response to specific signals. The emergence of new BPFDoor versions indicates ongoing refinement by threat actors. They have adapted to evade network security measures, such as static network signatures, by utilizing HTTPS requests to mask their activities.

Implications and Defensive Measures

The use of TinyShell and Rekoobe logic in BPFDoor samples highlights their modular nature, allowing them to adapt to target environments and facilitate data exfiltration. Additionally, a Rekoobe-based backdoor intercepts specific network traffic and uses process names linked to email security tools.

The AVERAT implant, delivered via an ELF binary dropper, further complicates detection. It uses SMTP for command-and-control, blending its operations with normal email traffic. Organizations are advised to audit their systems for unexpected network activities, especially focusing on processes that mimic known daemons or communicate over TCP port 25.

These findings underscore the sophisticated strategies employed by threat actors to exploit secure email gateways for intelligence gathering. The regional adaptation of these threats suggests that attackers are well-aware of the software running on targeted systems, tailoring their approach accordingly. As cybersecurity continues to evolve, staying vigilant and updating security protocols is crucial to countering these emerging threats.

The Hacker News Tags:Backdoors, BPFDoor, Cybersecurity, email security, Korea, Linux, Malware, Rapid7, Rekoobe, Taiwan, Telecom, Threat Actors

Post navigation

Previous Post: Enhancing Threat Monitoring with Intelligence-Led Approaches
Next Post: ASOS Investigates Unauthorized Notifications Breach

Related Posts

Experts Reports Sharp Increase in Automated Botnet Attacks Targeting PHP Servers and IoT Devices Experts Reports Sharp Increase in Automated Botnet Attacks Targeting PHP Servers and IoT Devices The Hacker News
Megalodon Campaign Targets Thousands of GitHub Repositories Megalodon Campaign Targets Thousands of GitHub Repositories The Hacker News
Mimo Hackers Exploit CVE-2025-32432 in Craft CMS to Deploy Cryptominer and Proxyware Mimo Hackers Exploit CVE-2025-32432 in Craft CMS to Deploy Cryptominer and Proxyware The Hacker News
China-Linked APTs Exploit SAP CVE-2025-31324 to Breach 581 Critical Systems Worldwide China-Linked APTs Exploit SAP CVE-2025-31324 to Breach 581 Critical Systems Worldwide The Hacker News
How Top CISOs Save Their SOCs from Alert Chaos to Never Miss Real Incidents How Top CISOs Save Their SOCs from Alert Chaos to Never Miss Real Incidents The Hacker News
Apple Patches Safari Vulnerability Also Exploited as Zero-Day in Google Chrome Apple Patches Safari Vulnerability Also Exploited as Zero-Day in Google Chrome The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Aembit Enhances Security for AI Agents in Enterprises
  • ASOS Investigates Unauthorized Notifications Breach
  • Linux Backdoors Mimic Email Tools to Evade Detection
  • Enhancing Threat Monitoring with Intelligence-Led Approaches
  • Phishing Platforms Target AI Chatbot Users for Credentials

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Aembit Enhances Security for AI Agents in Enterprises
  • ASOS Investigates Unauthorized Notifications Breach
  • Linux Backdoors Mimic Email Tools to Evade Detection
  • Enhancing Threat Monitoring with Intelligence-Led Approaches
  • Phishing Platforms Target AI Chatbot Users for Credentials

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark