Linux backdoors are posing a significant threat to telecom and network devices in South Korea and Taiwan. These backdoors are cleverly camouflaging themselves as email security tools to slip past detection mechanisms.
Impersonation Tactics of Threat Actors
Threat actors often use the names of legitimate system components to disguise malicious software. By adopting such names, they aim to make their software appear trustworthy or inconspicuous among legitimate processes. However, recent analyses by Rapid7 reveal that some backdoors are not just mimicking file names but are also posing as well-known email security solutions like SpamSniper and ShareTech, commonly used in South Korean and Taiwanese enterprises.
SpamSniper, as promoted by Jiran Group, is a leading email security tool in Korea, designed to shield organizations from spam, malware, and server threats. The backdoors exploit these trusted names to enhance their stealth capabilities.
Advanced Techniques and Variants
Among the newly identified threats are a BPFDoor variant and a BPF Rekoobe build targeting South Korean systems, alongside the AVERAT implant targeting Taiwanese devices. These backdoors adopt names of legitimate processes, such as those associated with anti-spam products, to avoid detection. Rapid7’s investigation links these activities to a threat group known as Red Menshen, active since 2021.
BPFDoor leverages Berkeley Packet Filter (BPF) functionality to monitor network traffic, activating only in response to specific signals. The emergence of new BPFDoor versions indicates ongoing refinement by threat actors. They have adapted to evade network security measures, such as static network signatures, by utilizing HTTPS requests to mask their activities.
Implications and Defensive Measures
The use of TinyShell and Rekoobe logic in BPFDoor samples highlights their modular nature, allowing them to adapt to target environments and facilitate data exfiltration. Additionally, a Rekoobe-based backdoor intercepts specific network traffic and uses process names linked to email security tools.
The AVERAT implant, delivered via an ELF binary dropper, further complicates detection. It uses SMTP for command-and-control, blending its operations with normal email traffic. Organizations are advised to audit their systems for unexpected network activities, especially focusing on processes that mimic known daemons or communicate over TCP port 25.
These findings underscore the sophisticated strategies employed by threat actors to exploit secure email gateways for intelligence gathering. The regional adaptation of these threats suggests that attackers are well-aware of the software running on targeted systems, tailoring their approach accordingly. As cybersecurity continues to evolve, staying vigilant and updating security protocols is crucial to countering these emerging threats.
