This precis summarizes the findings from the Rapid7 report on recent campaigns involving BPFDoor, Rekoobe, and AVERAT.
### **What Happened**
Threat actors have been executing sophisticated, modular campaigns targeting the network edge. These campaigns utilize a suite of Linux-based implants—most notably BPFDoor, Rekoobe, and a newer implant identified as AVERAT—to maintain long-term access to critical infrastructure. The attackers demonstrate high operational security by regionalizing their methods and heavily adapting their malware to blend into the specific environments they infiltrate.
### **Who Is Affected**
* **Primary Targets:** Telecommunications providers, network-edge operators, and organizations using mail-security appliances.
* **Devices Impacted:** Embedded and edge hardware, including network-attached storage (NAS) units (e.g., Synology), digital video recorders (DVRs), and other CCTV/IoT devices.
* **Geographic/Contextual Targeting:** The attackers tailor their camouflage to the target region; for example, they have been observed mimicking local software products, such as "SpamSniper" in South Korea, to avoid suspicion.
### **Security Implications**
* **Operational Resiliency:** By hijacking unpatched, end-of-life edge devices, attackers create a stable "operational relay" network that obscures the origin of their traffic, making attribution difficult.
* **Stealthy Persistence:** The implants often run entirely in memory, with no persistent footprint on disk, which helps them evade traditional file-based antivirus scanners.
* **Protocol Abuse:** By embedding command-and-control (C2) traffic within standard, expected protocols like SMTP (port 25) and DNS, the attackers significantly reduce the effectiveness of standard network monitoring that looks for anomalies in outbound traffic.
### **Technical Details**
* **AVERAT:** A modular Linux implant that beacons out via port 25, utilizing a custom encryption layer disguised as SMTP traffic to communicate with its C2 infrastructure. It provides advanced remote-access features, including file manipulation, process control, and interactive shell execution.
* **Passive Backdoors (BPFDoor/Rekoobe):** These implants use raw `PF_PACKET` sockets and BPF filters to remain dormant until they receive a specific "magic packet." Newer versions have become increasingly robust, incorporating multiple BPF filters to maintain stability on high-traffic nodes and even adding userland-level checks layered on top of kernel-level BPF gates.
* **Deployment:** Attackers typically use a dropper that writes scripts to staging areas (e.g., in `/sbin` or specific appliance-related directories) before executing the payload and deleting the source files.
### **What Defenders Should Know**
Defenders should prioritize visibility at the network edge, where these implants are most active:
* **Detection Indicators:**
* Monitor for raw packet sockets and the use of unusual BPF filters.
* Identify unexpected port-25 traffic originating from processes that are not part of the legitimate mail-handling stack.
* Watch for "process masquerading" where malicious binaries mimic legitimate system tools.
* Search for deleted but running binaries by checking if `/proc/<pid>/exe` points to a file marked as `(deleted)`.
* **Response Strategies:** If an intrusion is suspected on an edge appliance, do not reboot the device immediately if possible, as this will purge the memory-resident malware. Instead, focus on memory forensics and network traffic analysis.
* **Hardening:** Because these campaigns rely on exploiting vulnerabilities in edge devices, strict management of access controls and timely patching of end-of-life hardware are critical for preventing initial access.