As reported by The Hacker News, Rapid7 has uncovered new Linux backdoor variants targeting telecom and network infrastructure in South Korea and Taiwan — and the operational tradecraft on display is a masterclass in environment-aware evasion.
The campaign, attributed to the Red Menshen threat group (also tracked as Earth Bluecrow and DecisiveArchitect), introduces a refined BPFDoor variant, a new Rekoobe build, and a previously undocumented implant dubbed AVERAT. What sets this activity apart from generic process-name spoofing is the deliberate selection of regionally trusted security products — specifically SpamSniper and ShareTech — as camouflage. This is not opportunistic naming; it's tailored operational design meant to survive even environments where defenders are actively hunting for anomalies.
Why This Matters Beyond the Region
While the immediate targets are telecom and network appliances in South Korea and Taiwan, the evasion techniques here have global implications for any organization running Linux-based edge infrastructure.
The most significant tactical evolution is the shift in how BPFDoor's magic packet trigger is delivered. Earlier variants relied on Layer 4 network anomalies that were detectable via Suricata or Snort signatures. The new iteration wraps the trigger inside standard HTTPS POST requests, exploiting SSL offloading common in telecom edge environments. This means the malicious traffic is indistinguishable from routine web traffic to conventional deep packet inspection engines.
The combination of BPF-level packet inspection with HTTPS-wrapped triggers creates a nearly invisible command channel that can persist on edge devices for extended periods without generating network-level alerts.
Who Is at Risk
Why Traditional Detection Fails Here
Three layers of evasion compound to defeat standard security tooling:
- Process identity spoofing — impersonating trusted regional security products rather than generic system daemons, defeating allowlist-based process monitoring
- HTTPS-wrapped magic packets — bypassing network IDS/IPS signatures that previously caught Layer 4 anomalies
- BPF-level traffic inspection — operating below the visibility of most endpoint detection and response (EDR) agents, which typically focus on syscall-level activity rather than packet filter hooks
Defenders relying on network signatures alone will miss this traffic. Defenders relying on EDR alone may miss the BPF hook. The intersection is where this malware lives.
Shield53 Recommendations
- Audit BPF program usage on all Linux edge appliances — enumerate active BPF programs using
bpftool prog showand baseline legitimate entries. Investigate any unsigned or unexpected BPF programs immediately. - Validate security product installations — for SpamSniper, ShareTech, or any regional security tool, verify binary paths, hashes, and PID file locations against vendor-published values. Don't assume a process named after your security product IS your security product.
- Implement eBPF-based detection — tools like Tetragon or Falco can monitor BPF program loading events and flag suspicious hook installations in real time, providing visibility that traditional EDR lacks.
- Inspect SSL offloading infrastructure — ensure that edge proxies performing SSL termination are included in monitoring scope, and correlate outbound HTTPS traffic patterns from appliances that should not be initiating arbitrary external connections.
- Hunt for AVERAT dropper artifacts — Rapid7's report includes IOCs for the new implant. Prioritize threat hunting on Taiwanese and Korean network appliances for dropper activity preceding AVERAT deployment.
- Adopt behavioral baselining for edge devices — network appliances should have predictable communication patterns. Any new outbound HTTPS destinations from these devices warrant immediate investigation, regardless of whether the process name appears legitimate.
The broader lesson is clear: threat actors are studying your environment — your tooling, your product stack, your architecture — and designing implants to disappear into it. Generic detection is no longer sufficient. Defenders need the same environment-specific awareness that attackers are already demonstrating.