# Researchers identify Linux backdoors disguised as regional email security tools

_Published Tuesday, October 6, 2026 at 4:52 PM EDT · Security, Infrastructure · Latest · Tier 2 — Notable_

![Researchers identify Linux backdoors disguised as regional email security tools — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj42ncE2ZMHIbAm_fj5U9fqCYUvPwhyUiNbARM3CC5IxhnMXjIZ2ENa99UDGeaZqGPlqn53A7y7Nkz1ZxzzyykKxEb4GT0jxWhrar9Q5yPmBN1NL6599HRdbzbLSYf3WPuU7tkkY5eOsvhAT9dw-24DXuusztPyRr2H66840cWZx17MZ0B-rB877W19bgX1/s1700-nu-rw-lo-l85-e365/linux-spam.jpg)

Rapid7 researchers identified a new BPFDoor variant and a previously unreported Linux implant called AVERAT targeting telecom and network appliances in South Korea and Taiwan, The Hacker News reported. The malware impersonates regional email security products, including SpamSniper and ShareTech, to make its processes appear legitimate.

The BPFDoor variant can receive activation signals inside standard HTTPS requests through edge proxies, potentially evading conventional traffic inspection. AVERAT uses email protocol traffic for operator communications and supports file transfers, interactive shells, appliance reboots and proxy connections. Rapid7 said its command infrastructure resembles an operational relay network, but found no evidence linking it to known networks of that kind.

## Sources

- [The Hacker News](https://thehackernews.com/2026/10/linux-backdoors-impersonate-email.html)

---
Canonical: https://techandbusiness.org/newswire/CpYoCjCAuU-Om3W-EWNw-W
Published: 2026-10-06T20:52:15.527Z
Story chronology: 2026-10-06T18:24:25.000Z
Retrieved: 2026-10-06T23:09:02.826Z
Publisher: Tech & Business (techandbusiness.org)
