Post

SMTP is the key BPFDoor and AVERAT hitting the network edge

SMTP is the key BPFDoor and AVERAT hitting the network edge

SMTP is the Key: BPFDoor and AVERAT Hitting the Network Edge 🚀

Rapid7 has tracked a set of Linux samples that seamlessly blend into the software and device conventions of the telecom environments they target. This set includes a newly observed BPFDoor variant, a BPF Rekoobe build seen against South Korean targets, a dropper, and six builds of a Linux implant we track as AVERAT, deployed against Taiwanese appliances.

The chain utilizes two binaries. A dropper writes a shell script to the appliance’s storage mount and executes it. The script stages both payloads into /sbin under the names ntpdate and udevds, launches them, and deletes each file ten seconds later while the processes continue running. The common thread is regionalized disguise: each sample is aware of the vendor’s software running on the targeted systems and implements process spoofing accordingly. Passive BPF implants avoid conventional port scans; while outbound beacons hide inside ordinary DNS, TCP, and traffic, the threat actor(s) leverage SMTP to stay under the radar. Telecommunications and network-edge operators are most affected, including embedded devices such as CCTV and DVR systems that can sit close to the network core.

Earlier BPFDoor variants relied on raw “magic bytes” (like 0x7255 or 0x5293) sitting in the TCP or UDP headers. Once security vendors wrote static network signatures (Suricata/Snort) to detect these Layer 4 anomalies, the operators began targeting the edge proxies. By wrapping the magic packet in standard HTTPS POST requests and relying on SSL offloading common in telecom environments, the trigger can be delivered to the BPFDoor-infected node in a way that may evade conventional deep packet inspection. To solve this, the new controller sends fake, benign-looking web requests (e.g., POST /admin/login.aspx?id=99990) that are mathematically padded. This guarantees that the string “9999” lands at exactly offset 26 of the TCP payload consistently. The backdoor uses this “9999” as a reference point, dynamically scans for the \r\n\r\n terminator, and extracts the hex-encoded command payload from the HTTP body. When running, the controller spoofs the identity of /usr/sbin/abrtd via set_proc_name and PR_SET_NAME.

A new BPFDoor variant tied to the South Korean cluster was observed. These BPFDoor variants create a raw PF_PACKET socket, attaching a classic BPF filter matching Rapid7 Variant F and using magic bytes 0x6693 (UDP), 0x4274 (TCP), and 0x7820 (ICMP). On a match, the implant extracts the source address and connects back to the sender if the password is gZbpx0, opens a bind shell if the password is sT21xf, and otherwise defaults to a UDP knock. The SpamSniper /var/run/spamsniper.pid mutex, together with the sample provenance, ties this build to the South Korean cluster. SpamSniper is antispam software used mainly in South Korea, so this masquerade is consistent with targeting a Korean mail or telecom environment. Additionally, the sample 652508a9cf40bee883dc0e5e219dfeba71fe7dac591d01c89f74c21f73b4963f is a Rekoobe-based backdoor. It attaches a 26 BPF instruction filter, sniffing for TCP/UDP/SCTP IPv4 and UDP IPv6 traffic with source and destination ports equal to 25. The implant authors understood exactly what traffic profile would be invisible on this specific class of host. By setting variables like VIMINIT="set viminfo=", HISTFILE=/dev/null, HISTSIZE=0, and HISTFILESIZE=0, the malware ensures that the attacker’s commands are not logged to bash history nor to vim logs.

A dropper likely built for ShareTech appliances was identified. The dropper (update:2bedc26d4b29b435c21962beed7db21188a0219a0d28334bba8b4fb1656d7b15) is an x86-64 ELF with a minimal import table. It is a local installer, run after access is already established. It carries four AES-128-ECB blobs keyed on the first sixteen bytes of SHA1(“ShareTech”), or 6C CA D5 17 0E 3D B8 17 B3 DF 52 E0 D9 71 B1 48.

For more detailed insights, check out the full article here: Read full article

This post is licensed under CC BY 4.0 by the author.