AVERAT beacons its controller over SMTP every 600 to 699 seconds to a server named "mx.zxopfds[.]com," using port 25 — a deliberate choice to hide malicious control traffic inside ordinary mail protocols.
AVERAT's SMTP-based C2 and the ShareTech vector
Rapid7's analysis identifies AVERAT as a previously unreported Linux implant delivered by an ELF dropper staged inside a ShareTech appliance's "/addpkg/sbin/" add-on package directory. The dropper derives an encryption key from the string "ShareTech" to decrypt a shell script that stages two binaries: "ntpdate" (the dropper) and "udevds" (the AVERAT payload). Both files are deleted 10 seconds later after execution.
AVERAT's operation is centered on SMTP: it periodically polls a C2 server ("mx.zxopfds[.]com") over TCP port 25 on a 600–699 second interval. Rapid7 reports the implant reads server details and its beacon interval from an encrypted configuration. The backdoor supports a broad command set, including directory enumeration, file upload and download (with resume), recursive deletion and traversal, process enumeration and termination, opening interactive shells (up to 10 concurrent sessions), loading/unloading shared-object modules, rebooting the appliance, and runtime modification of C2 tables. Rapid7 documents the command codes explicitly, for example 20 (enumerate directory contents), 21 (download a file, with resume), 22 (upload a file in chunks), 912 (open an interactive shell session), 1010 (load or unload a shared object), and 842 (overwrite the C2 host and port tables at runtime).
BPFDoor variants, BPF filters, and HTTPS-wrapped triggers
On South Korean systems, Rapid7 observed new BPFDoor variants and a BPF Rekoobe build that abuse Linux's Berkeley Packet Filter (BPF) to inspect incoming traffic and activate only when a magic packet is detected. According to Rapid7, this class of implant was altered after previous public detections. "Once security vendors wrote static network signatures (Suricata/Snort) to detect these Layer 4 anomalies, the operators began targeting the edge proxies," Rapid7 said — wrapping the magic packet in standard HTTPS POST requests and relying on SSL offloading common in telecom environments so the trigger can reach BPFDoor-infected nodes while evading conventional deep packet inspection.
One Rekoobe-based BPF backdoor intercepted TCP/UDP/SCTP IPv4 and UDP IPv6 traffic and specifically targeted flows where source and destination ports were equal to 25. The behaviour demonstrates two parallel evasion choices: passive packet filtering via BPF, and transport-layer camouflage that blends malicious triggers into legitimate-looking HTTPS or mail flows.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildProcess spoofing: SpamSniper, ora_ppmond, and common daemons
Rather than merely reusing benign file names, Rapid7 found samples that impersonate enterprise email security products. Several BPFDoor variants observed against South Korean systems adopt the PID file name and other conventions associated with SpamSniper, which vendor Jiran Group advertises as "Korea's leading email security solution" that defends organizations against spam, malware, and server attacks. Other artifacts set their process name to "ora_ppmond," echoing the "ora_pmon_*" naming convention tied to Oracle Database PMON processes used in telecom subscriber and provisioning platforms.
"Across the samples, each component adopts names and conventions designed to look unremarkable in the environment it targets," Rapid7 said. The intent is explicit: disguise privileged implants as trusted or routine services so they are overlooked by operators and automated controls.
Operational links: Rekoobe, TinyShell, and Red Menshen
Rapid7 notes that BPFDoor samples observed in these campaigns act as a modular framework, integrating TinyShell and Rekoobe logic to support exfiltration. "These samples show BPFDoor operating as a modular framework that adapts to the telecom layer it targets, integrating TinyShell and Rekoobe logic to support exfiltration," Rapid7 explained. Once triggered, a BPFDoor sample can launch a TinyShell session and provide interactive shell, upload, and download capabilities.
BPFDoor and its many iterations were the subject of an earlier Rapid7 analysis linking the activity to a threat cluster tracked as Red Menshen (also referenced as Earth Bluecrow, DecisiveArchitect, and Red Dev 18), which has targeted telecom providers across the Middle East and Asia since 2021. Rapid7 also flagged overlaps in tooling and tradecraft with other China-nexus clusters previously observed using TinyShell.
What this means for technologists, procurement leaders, and network operators
- Technologists and security teams: Review for unexpected raw packet sockets and BPF filters on Linux systems that do not require packet capture; audit outbound TCP port 25 connections from processes that are not mail services; and scan for processes posing as common daemons.
- Affected enterprises and procurement leaders: Note the campaign's use of real vendor names (SpamSniper, ShareTech) inside target environments; verify the integrity of add-on package directories on appliances and insist on supply-chain controls that detect unusual installers and encrypted droppers.
- Network operators and appliance managers: Restrict management access to routers, DVRs, and other edge appliances, and be aware that SSL offloading and proxying at the edge can be abused to smuggle activation packets past conventional DPI.
The record Rapid7 lays out is specific and unsettling: the adversary adapts both how it listens (BPF filters, magic packets wrapped in HTTPS) and what it pretends to be (email security and database daemons). Defenders are left to harden visibility at the packet-capture and process levels — and to treat ordinary mail ports and trusted process names as potential camouflage, not guarantees of benignity.




