Skip to main content
Emerging ThreatsMalware & Ransomware

Malicious Backdoors Infiltrate Telecoms via Email Traffic Disguise

Mail security gateway device centered in a clean, neutral background.

"On a mail security gateway, where outbound mail is the device's core job, Rapid7 said the traffic is indistinguishable from legitimate work in flow records." — Rapid7

AVERAT: hiding in plain sight on TCP port 25 and SMTP

Research published October 2 by Rapid7 describes an implant family called AVERAT that deliberately blends into mail traffic. AVERAT opens an outbound Transmission Control Protocol (TCP) connection on port 25 and speaks Simple Mail Transfer Protocol (SMTP). It issues an EHLO command and explicitly requests STARTTLS before commencing its own encrypted session, behavior that mirrors a legitimate mail client initiating encrypted mail delivery.

The implant checks in every 600 to 699 seconds and supports a broad command set: file transfers, process termination, up to ten concurrent shell sessions, and proxy or port‑forwarding channels. On devices whose primary function is outbound mail — mail security gateways, for example — Rapid7 warned the resulting flows can be indistinguishable from expected work when viewed in flow records.

BPF Rekoobe and BPFDoor: process masquerade and trigger mechanics

Rapid7 documented two different BPF-based toolsets used against targets in South Korea. A BPF Rekoobe sample watches specifically for packets with both source and destination ports equal to 25, and it names its processes after components of SpamSniper, a South Korean anti-spam product. Rapid7 noted that firewall rules allowing mail relay between servers could let such a trigger packet reach the implant before stateful inspection occurs.

Separately, Rapid7 observed BPFDoor variants that also impersonate SpamSniper; another BPFDoor sample named itself after processes on Oracle-based telecom subscriber platforms. The researcher further described a BPFDoor controller that wraps its trigger inside HTTPS POST requests, a packaging that may let the trigger traverse edge proxies and evade conventional deep-packet inspection.

Hijacked relays in Taiwan: Synology NAS, a small-business box, and a Dahua recorder

Against Taiwanese appliances, Rapid7 tracked three AVERAT builds reporting to hardcoded addresses hosted on three compromised third-party devices: a Synology NAS, an obsolete small-business appliance, and a Dahua video recorder. Rapid7 found that all three had been configured to run an identical PPTP VPN service — a service the researchers believe the operators installed — creating routes into each victim's network.

Those devices served as relays for the implant infrastructure, effectively positioning easy-to-reach edge appliances as persistence and transit points for operators seeking to reach internal networks.

Overlap with CISA's April 2026 advisory on ORB networks, but attribution remains open

Rapid7 reported that the relays it observed match the device profile described in an April 2026 advisory published by the US Cybersecurity and Infrastructure Security Agency (CISA) and partners on China‑nexus covert networks, known as operational relay box (ORB) networks. At the same time, Rapid7 said it found no overlap with any named ORB network and that attribution remains ongoing.

What this means for mail appliance operators, telecoms, and edge‑device managers

  • Mail appliance operators: watch for outbound connections on TCP port 25 originating from processes that are not legitimate mail services, and remember that SMTP-style handshakes (EHLO/STARTTLS) can be mimicked to hide command-and-control traffic.
  • Telecom and network-edge teams: inspect for unexpected Berkeley Packet Filter (BPF) filters and raw packet sockets; attackers are using BPF-based implants and naming conventions that imitate common daemons to avoid simple detection.
  • Edge-device managers (routers, DVRs, NAS): restrict management access and inventory remote-access services — Rapid7 found identical PPTP VPN services installed on compromised relays, and recommended restricting management access to routers, DVRs and other edge appliances.

Rapid7's operational recommendations cohere around a single point: these implants exploit operational permissiveness at the edge and the functional expectations of mail appliances to remain concealed. Investigate unexpected raw packet sockets and BPF filters, flag outbound port 25 connections from non-mail processes, and look for processes posing as well-known daemons. Those steps, Rapid7 argues, are the first lines of defense against a set of implants that intentionally masquerade as legitimate mail traffic.

Attribution remains ongoing, and Rapid7 emphasized that the traffic and process-level deception make detection difficult on devices whose job is to carry mail. The combination of SMTP mimicry, BPF triggers, and hijacked third-party relays raises a concrete operational question: can defenders tighten edge controls and telemetry enough to see through an attack that deliberately looks like legitimate mail?

Original story