Hackers Built Malware That Perfectly Mimics Korean and Taiwanese Email Security Boxes
Rapid7 has documented a set of Linux implants so well-tailored to their target appliances that they impersonate specific product files, ports, and processes used in real telecom environments across South Korea and Taiwan.

Key points
- Rapid7 identified a cluster of Linux malware samples in 2026 that mimic the file names and process identities of email security appliances sold to Korean and Taiwanese enterprises.
- A newly tracked implant called AVERAT, deployed against Taiwanese ShareTech appliances, communicates with its operators over TCP port 25, the standard port for email, so the traffic looks like ordinary mail.
- BPFDoor variants in the South Korea campaign impersonate SpamSniper, an anti-spam product used by more than 6,000 organisations as of July 2023, including South Korean government ministries.
- The dropper deletes its own files ten seconds after launch but leaves the malicious processes running in memory, meaning nothing suspicious stays on disk.
- Detection requires looking for processes whose on-disk files have already been deleted, a condition Linux marks with a "(deleted)" label in the process directory.
Some malware pretends to be something harmless by borrowing a convincing name. This goes considerably further.
Rapid7 has documented a set of Linux malware samples that don't just pick familiar-sounding names. They reproduce the specific process files, network ports, and operating habits of real email security appliances sold in South Korea and Taiwan, fitting into telecom networks the way a spare part fits into the machine it was built for. We first covered BPFDoor on 30 July 2026, and these new variants represent a marked escalation in how precisely the tooling is built around its targets.
What exactly is happening here?
Two related campaigns are hitting network edge appliances, meaning the hardware boxes that sit between an organisation's internal systems and the open internet. These boxes handle email filtering and security, occupying a trusted position: corporate firewalls tend to wave them through without much scrutiny.
BPFDoor, a long-running backdoor (a hidden way for outsiders to control an infected machine remotely) linked to Chinese intelligence operations against global telecoms, sits at the centre of the South Korea campaign. Its newest variants impersonate SpamSniper, a real Korean anti-spam product used by more than 6,000 organisations as of July 2023. One further BPFDoor sample poses as a background process associated with Oracle telecom subscriber platforms. Alongside these, Rapid7 found a build of Rekoobe, an older remote-access tool, also disguised as SpamSniper, copying its process-ID file and system service names.
The Taiwan campaign uses a dropper, a small program whose only job is to install other malware. It takes on the appearance of a ShareTech Information appliance. ShareTech is a Taiwanese mail-security vendor serving large enterprises and government bodies across Asia. The dropper installs AVERAT, a modular remote-access tool that Rapid7 is tracking for the first time, plus a copy of itself as a watchdog.
Ten seconds after installation, the dropper deletes every file it placed on disk. The processes keep running in memory. Standard file-scanning tools find nothing because nothing is there to scan.
Why is this so hard to catch?
Three things stack against defenders. First, these appliances are closed boxes: vendors manage them, and organisations cannot install the endpoint-monitoring software (EDR, meaning software that watches for suspicious behaviour on a device) that they'd run on a regular laptop or server.
Second, the malware's command traffic rides on TCP port 25. Port 25 is the traditional channel for SMTP, the standard protocol that mail servers use to send email to each other. AVERAT even opens its sessions using normal SMTP conventions before switching to an encrypted channel. From the outside, it looks like routine mail going to a distant mail server.
Third, the infrastructure the malware phones home to is made up of hijacked digital video recorders and network-attached storage devices, not attacker-owned servers, so IP-address blocklists don't help.
Rapid7's vice president of intelligence, Christiaan Beek, told Dark Reading that the most practical detection step is almost disarmingly simple: look for processes flagged as "(deleted)" in the Linux process directory, which signals that the on-disk file behind a running process is gone. Watching outbound port-25 traffic from devices that aren't actually mail servers is the other routine check a security team can run.
| Campaign | Target appliance | Key malware | C2 channel |
|---|---|---|---|
| South Korea | SpamSniper, Oracle telecom platforms | BPFDoor variants, Rekoobe | BPF passive socket, ICMP |
| Taiwan | ShareTech mail appliances | AVERAT (6 builds) | TCP port 25 (SMTP) |
| Both | Linux edge hardware | Shared dropper | Deleted-on-launch files |
The encryption key the dropper uses is derived from the string "ShareTech", which is either a clue or deliberate misdirection. Either way, it shows how precisely these tools were built for their targets.
Whoever built these implants studied their victims' products closely enough to pass as those products. Patient, targeted espionage work. Telecom operators across Asia and their suppliers anywhere in the world should be treating unmonitored edge appliances as a live exposure right now, not a future concern.
Common questions
Does this affect ordinary internet users?
Not directly. The targets are network appliances used by large telecoms and enterprises, not home routers or personal devices. The long-term goal of this kind of campaign is intelligence gathering from organisations that run communications infrastructure.
What should IT teams at affected organisations do?
Rapid7's advisory recommends checking for processes marked "(deleted)" under the Linux /proc directory, looking for unexpected raw packet sockets, and checking for dropper artefacts in the /HDD/ms6x2xTo64/ directory. Restricting management access to edge appliances and monitoring any outbound port-25 traffic from devices that aren't designated mail servers are the two most actionable controls.



