Image: rapid7.com · rights & removal
SMTP is the key: BPFDoor and AVERAT hitting the network edge
Reporting by Rapid7 BlogRead the original at rapid7.com
Executive Summary
The provided material details a set of Linux samples and exploitation techniques developed by Rapid7, focusing on BPFDoor variants and an implant named AVERAT deployed against telecom and network-edge appliances. The attack chain involves a dropper that stages payloads into `/sbin` using shell scripting and deletes them, leaving running processes without on-disk images. Communication employs methods to evade detection, including hiding C2 traffic within standard protocols like DNS and SMTP, and using process masquerading to blend with legitimate system functions.
The analysis reveals two primary attack vectors: a BPFDoor-based mechanism that uses crafted network packets (wrapped in HTTPS) for triggering and another Rekoobe-based backdoor implementation that utilizes custom XOR routines and process name spoofing within the Linux environment. The communication infrastructure leverages consumer-grade CPE devices—NAS, ADSL/FTTH appliances, and DVRs—as relay points, connecting through PPTP on port 1723 to establish C2 channels.
The focus is heavily placed on the network edge, specifically targeting mail security appliances situated near the core network, which operate as relays for traffic obfuscation. Detection guidance emphasizes hunting for fileless artifacts in memory and staging sequences related to temporary files and process manipulation, alongside monitoring outbound SMTP activity to mail-role hosts.
Facts Only
* A set of Linux samples was tracked blending into telecom environment conventions.
* The set included a BPFDoor variant, a BPF Rekoobe build, a dropper, and six builds of the Linux implant named AVERAT.
* The chain uses a dropper to write a shell script to storage, stage payloads into `/sbin` as `ntpdate` and `udevds`, execute them, and delete the files after ten seconds.
* The dropper derives an encryption key from the string "ShareTech."
* BPFDoor variants impersonate SpamSniper PID files and rotate through ten Linux daemon names for disguise.
* Passive BPF implants hide outbound beacons in DNS, TCP, and traffic, leveraging SMTP to remain under radar.
* The core mechanism involves a controller that uses fake web requests to extract payloads via HTTPS POST tunneling.
* BPFDoor samples use custom BPF filters matching specific magic bytes (e.g., 0x6693 for UDP).
* One BPF sample spoofs the process name to `orappmond` to mimic Oracle-backed platforms.
* The AVERAT implant uses an encrypted blob derived from XOR routines for configuration and communication keys.
* Command codes exist for operations like downloading files, uploading files, terminating processes, and opening shell sessions.
* C2 infrastructure utilized consumer CPE devices (NAS, DVRs) relaying traffic over PPTP on port 1723.
* Specific file indicators include `/HDD/ms6x2xTo64/execProcEnd` and state files in `/var/lib/.db`.
Full Take
The narrative presents a sophisticated evolution of malware designed for stealth within infrastructure environments, demonstrating an acute understanding of the operational context. The shift from static packet manipulation to dynamic, layered frameworks like BPFDoor and Rekoobe highlights an operational capability where exploits are tailored not just to bypass perimeter defenses but to blend seamlessly into established network protocols and vendor conventions—specifically targeting the unique traffic profiles of telecom and embedded systems.
The effectiveness lies in modularity: the dropper handles staging and execution via ephemeral files, while the core implants adapt their signaling (BPF for network triggers) and persistence (AVERAT state files) based on the target environment. This layered approach creates a high bar for detection because artifacts are deliberately ephemeral or disguised as legitimate operational noise; file-based persistence is avoided in favor of memory-resident execution, forcing defenders to shift focus from static IOCs to dynamic process behavior and network flow anomalies.
The implications point toward an attack methodology that weaponizes the "trust" inherent in edge devices. By utilizing end-of-life or unpatched consumer hardware as C2 relays, the threat actor exploits the fact that these devices are often trusted implicitly within larger network structures, making their presence less likely to trigger traditional security alerts than activity on dedicated server assets. The persistence of command and control via subtle SMTP signaling further entrenches the concept of leveraging "normal" traffic flow for covert command relay rather than relying on anomalous protocol use.
Bridge Questions: What is the long-term viability of relying on endpoint detection against systems where execution and persistence are intentionally designed to be ephemeral? How does the reliance on device-class assets as relays change the risk calculation for network segmentation policies? What observable differences exist in defensive posture when distinguishing between legitimate operational traffic and activity masquerading as it, especially concerning Layer 4 protocols used by edge hardware?
From the original · Rapid7 Blog
Overview Rapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a newly observed BPFDoor variant, a BPF Rekoobe build seen against South Korean targets, a dropper, and six builds of a Linux implant we track as AVERAT, deployed against Taiwanese appliances.Read the full story at rapid7.com
