Rapid7 Details BPFDoor and AVERAT Activity Targeting Network-Edge Appliances

· Original article ↗

Summary

Rapid7 analyzes BPFDoor, Rekoobe, and AVERAT samples targeting telecom and mail-security appliances in South Korea and Taiwan, detailing SMTP-based command-and-control, stealth techniques, compromised-device relays, and detection opportunities.

Key points

  • The research covers a newly observed BPFDoor variant, a BPF Rekoobe build associated with South Korean targets, and six AVERAT builds deployed against Taiwanese appliances.
  • AVERAT uses outbound SMTP on port 25, including EHLO and STARTTLS, to disguise encrypted command-and-control traffic as normal mail activity; it can run shells, transfer files, and proxy connections.
  • BPFDoor and Rekoobe use raw sockets and BPF filters to detect magic-packet triggers, with process-name spoofing tailored to software found in target environments.
  • A dropper stages payloads under ordinary-looking names in /sbin, launches them, then deletes the files while the processes continue running; its watchdog can recreate staging artifacts.
  • The AVERAT infrastructure includes compromised NAS, network appliances, and a DVR used as relays. Rapid7 says the device profile matches broader ORB patterns but found no overlap confirming membership in a named ORB network.
  • Defenders should investigate unexpected raw packet sockets and BPF filters, unlinked running executables, suspicious port-25 callbacks, process masquerading, and the documented staging paths and process sequence.

Article Details

Attack Vectors
  • A local dropper, run after access was established, stages itself and AVERAT on an appliance, launches both, and deletes the staged files while the processes continue running.
  • BPFDoor and Rekoobe use packet filters to wait for specially crafted traffic before opening interactive access. A newer BPFDoor controller can carry its trigger in an HTTPS POST through an edge proxy.
  • AVERAT uses outbound SMTP on port 25, requests STARTTLS, and then establishes its own encrypted command-and-control session. Its configured relays are compromised Taiwanese consumer or SMB devices.
  • The BPF Rekoobe sample filters for traffic with both source and destination port 25, matching an SMTP relay traffic pattern expected on a SpamSniper appliance.
Defensive Notes
  • Hunt for processes whose /proc/<pid>/exe target ends in (deleted), and inspect executable memory mappings without backing files.
  • Alert on the appliance staging directory, a shell script with a .php extension, watchdog markers, and the sequence of copying binaries into /sbin, executing them, and deleting them roughly ten seconds later.
  • Investigate unexpected raw packet sockets and classic BPF filters, and review outbound port-25 connections from processes that are not mail services.
  • Preserve short-lived staged binaries and collect process arguments, open file descriptors, socket metadata, and historical DNS records.
  • Restrict management access to routers, DVRs, and other edge appliances; monitor NFS or SMB mounts that could permit an adjacent host to write executables.

Indicators of compromise

TypeIndicatorContext
HOSTNAMEmx[.]zxopfds[.]comAVERAT command-and-control hostname.
HOSTNAMEmx1[.]wwstifsteel[.]comAVERAT command-and-control hostname.
HOSTNAMEspam[.]suwaccqi[.]comAVERAT command-and-control hostname.
IPV41[.]34[.]200[.]85Compromised third-party Dahua recorder used as an AVERAT C2 relay.
IPV4122[.]116[.]138[.]33Compromised third-party embedded appliance used as an AVERAT C2 relay.
IPV459[.]125[.]211[.]65Compromised third-party Synology NAS used as an AVERAT C2 relay.
SHA2562bedc26d4b29b435c21962beed7db21188a0219a0d28334bba8b4fb1656d7b15ShareTech-appliance dropper hash.
SHA2562fe2dd402ee6f9c578fce6dd4b36daaa407e99133e5dd502f2afca80feb60150AVERAT implant hash.
SHA2564435fcd6862921092614dbeaa880e4192352984686ebcd98f0ba13ee8e226ef9Data-plane BPFDoor sample hash.
SHA2564925bcca085ec504f51191645da278d8e96698d91f3c6df44146336c697b4de8AVERAT implant hash.
SHA256652508a9cf40bee883dc0e5e219dfeba71fe7dac591d01c89f74c21f73b4963fRekoobe backdoor hash; its BPF filter matches traffic using port 25 in both directions.
SHA2567e667ba5f9df912e02275d3cfe3809d16f822fe776f4035c84b118ebd925b1b5SpamSniper-disguised BPFDoor sniffer hash.
SHA256925c041807d4fb9dfe2ad84f963c2a4c60ea1289f6a0bdccbfb944478ffc2cf2AVERAT implant hash.
SHA256a37ea9897221d4495b538de72b74f2aa1d2ff09b7b6dcedd395aee58931adbf3SpamSniper-disguised BPFDoor sniffer hash.
SHA256a4379e115d3c4420f5d4b92561022d6e0897990e7297be65c033d47de68e6a6aAVERAT implant hash.
SHA256a65048eb30661e27f8edc2dd8d8c77ec87faec1f1750f6e04e7ecaf069a32858AVERAT implant hash.
SHA256a6f3b7f932761fb1fd5e74123f2482e36c65dd13e769af2ce08c65da195bfa7aData-plane BPFDoor sample hash.
SHA256bf8135f46ecedfe5bd06fcecbb2e721c2367ff765b18f4aa3f868e6597f49e47AVERAT implant hash.

MITRE ATT&CK

T1016 · System Network Configuration DiscoveryAVERAT check-ins report network interfaces.T1027 · Obfuscated Files or InformationBPFDoor hides strings with a rotating substitution alphabet, while AVERAT keeps operational configuration in an encrypted blob.T1027.013 · Encrypted/Encoded FileThe dropper carries encrypted blobs containing paths and a script; AVERAT stores keys, hosts, ports, and timing state in an encrypted configuration blob.T1033 · System Owner/User DiscoveryAVERAT check-ins report the current user and logged-in users.T1036.004 · Masquerade Task or ServiceBPFDoor and Rekoobe samples rewrite their process identities to resemble Linux or appliance-specific daemons.T1036.005 · Match Legitimate Resource Name or LocationThe dropper stages malicious binaries in /sbin as ntpdate and udevds before executing them.T1037 · Boot or Logon Initialization ScriptsRapid7 says the dropper's location in the appliance add-on package directory makes relaunch by firmware package startup at boot very likely.T1041 · Exfiltration Over C2 ChannelAVERAT supports downloading files from an infected host over its command-and-control connection.T1057 · Process DiscoveryAVERAT can enumerate running processes and their command lines.T1059.004 · Unix ShellThe dropper executes a shell script that stages its payloads; AVERAT can also open interactive shell sessions.T1070.003 · Clear Command HistoryThe Rekoobe-based sample sets HISTFILE=/dev/null and zeroes history-size variables to prevent commands from entering shell history.T1070.004 · File DeletionThe dropper's script deletes both staged /sbin binaries about ten seconds after launching them.T1071.003 · Mail ProtocolsAVERAT connects outbound on port 25, issues EHLO, and requests STARTTLS before its encrypted C2 session.T1082 · System Information DiscoveryAVERAT check-ins report the host's name and OS version.T1083 · File and Directory DiscoveryAVERAT commands enumerate directory contents and recursively walk directory trees.T1090 · ProxyAVERAT can open a proxy or port-forward channel through an infected appliance.T1105 · Ingress Tool TransferAVERAT supports uploading files to an infected host in chunks.T1129 · Shared ModulesAVERAT has a command to load or unload a shared-object module.T1133 · External Remote ServicesAll three AVERAT relays expose PPTP on port 1723; Rapid7 assesses the matching PPTP service as operator-installed for VPN access.T1140 · Deobfuscate/Decode Files or InformationThe dropper decrypts its embedded blobs to obtain staging paths and a script; AVERAT decrypts its operational configuration.T1205 · Traffic SignalingBPFDoor waits for magic packets, including triggers carried in crafted HTTPS POST requests through edge proxies.T1205.002 · Socket FiltersBPFDoor and BPF Rekoobe attach packet filters that select specially crafted trigger traffic before the implants respond.T1480 · Execution GuardrailsThe dropper takes its installation branch only if /tmp/flag exists and its .php staging script does not.T1529 · System Shutdown/RebootAVERAT has a command to reboot the appliance after flushing filesystem buffers.T1562.004 · Disable or Modify System FirewallThe data-plane BPFDoor samples contain iptables NAT-redirect staging and teardown logic.T1564.001 · Hidden Files and DirectoriesAVERAT stores its callback interval in a hidden state file such as /var/lib/.db.T1573.001 · Symmetric CryptographyAVERAT establishes an encrypted session after STARTTLS using shared secrets; the Rekoobe-based sample uses AES-CBC for its command interface.T1584.008 · Network DevicesThe article identifies three compromised NAS, embedded-appliance, and recorder hosts repurposed as AVERAT C2 relays.

Malware

Vendors

Products

Tools

Countries

Industries

Related Articles