Linux implants copy mail appliance names and port 25 traffic. Rapid7's 12 hashes do not say how they got in
Rapid7 Intelligence says Linux implants imitate Korean and Taiwanese mail security appliances, down to a product PID file and port 25 mail traffic, and lists 12 hashes. It does not say how they got on, how many appliances were hit or whether any UK organisation is affected.
By Parminder Kumar Sharma · · 18 min read

Twelve hashes, ten seconds and no stated way in
Rapid7 Intelligence's report of 2 October 2026 lists 12 distinct SHA-256 hashes in its indicator tables: five in what it calls a South Korean cluster and seven in a Taiwan cluster. That count is derived here from Rapid7's Tables 7 and 8; the report's overview prose lists a BPFdoor variant, a Rekoobe build, a dropper and six AVERAT builds, which is nine, while the tables carry four BPFdoor hashes. For the Taiwan cluster, the staging script Rapid7 reproduces copies each payload into a system directory, starts it, waits ten seconds and deletes the file. The process carries on. That is why Rapid7 writes that file-based detection on the appliance "is unlikely to succeed", and why nobody who runs these boxes can settle the question by listing the filesystem.
What those numbers do not establish matters more. They do not establish how any implant reached an appliance: Rapid7 calls the dropper "a local installer, run after access is already established", and the report names no vulnerability, no CVE and no exploit in either vendor's software. They do not establish how many appliances were taken, when any sample was first seen, or whether any organisation in the UK is affected. And they do not show that a SpamSniper or ShareTech product is flawed. The report describes what the implants copy. It does not describe a failure in the thing they copy.
All of this was read at about 12:00 BST on Sunday 4 October 2026, two days after Rapid7 published, and any of it can be overtaken. The better way to read the report is as a catalogue of labels. A process name, a PID file, a service name and a firewall-allowed port are what a person looks at when deciding that a box is behaving. Rapid7 documents samples built to match each one. "It is the mail security appliance" is the assumption the malware is built to exploit.
Stated and not stated
The table is built from Rapid7's own post, SMTP is the key: BPFDoor and AVERAT hitting the network edge, dated and last updated 2 October 2026 and read in full as HTML. Where a cell says none read, it means no vendor document I could reach confirms the point.
What Rapid7 Intelligence's report of 2 October 2026 states and leaves open, read on 4 October 2026 at about 12:00 BST. Counts marked derived are this briefing's own.
- Question
- What was found
- Stated by Rapid7
- Samples of BPFdoor, a BPF Rekoobe build, one dropper and six AVERAT builds. 12 hashes in its tables (derived).
- Not stated
- How the samples were obtained, when each was first seen, or on how many machines they ran.
- Question
- What they imitate
- Stated by Rapid7
- SpamSniper's PID file and, in Rapid7's labelling, its product paths. A process name used on Oracle-backed telecom platforms. The name ShareTech, used to seed the dropper's key.
- Not stated
- A ShareTech model. Any vendor document showing the paths exist on a genuine appliance: none read.
- Question
- How they got on
- Stated by Rapid7
- The dropper is a local installer, run after access is established, and it starts only if a flag file already exists.
- Not stated
- What established access, what creates the flag file, or whether any flaw in either vendor's software was used.
- Question
- Victims
- Stated by Rapid7
- The Rekoobe build was seen against South Korean targets and AVERAT deployed against Taiwanese appliances. Three relay devices in Taiwan are compromised third-party equipment, in Rapid7's assessment.
- Not stated
- Any victim appliance by name or sector, a count, how seen or deployed was established, or a country total.
- Question
- Who is behind it
- Stated by Rapid7
- The 2 October report refers to the threat-actor(s) and says attribution should remain an ongoing assessment.
- Not stated
- A named actor or a confidence level for this activity. No overlap with any named covert network was found.
- Question
- Persistence
- Stated by Rapid7
- Payloads run from memory. Rapid7 infers that the appliance's add-on package start-up very likely relaunches the dropper at boot.
- Not stated
- A vendor document confirming that start-up behaviour: none read.
- Question
- UK exposure
- Stated by Rapid7
- Telecommunications and network-edge operators are most affected, with no country given.
- Not stated
- Any UK victim, customer or deployment of either product.
| Question | Stated by Rapid7 | Not stated |
|---|---|---|
| What was found | Samples of BPFdoor, a BPF Rekoobe build, one dropper and six AVERAT builds. 12 hashes in its tables (derived). | How the samples were obtained, when each was first seen, or on how many machines they ran. |
| What they imitate | SpamSniper's PID file and, in Rapid7's labelling, its product paths. A process name used on Oracle-backed telecom platforms. The name ShareTech, used to seed the dropper's key. | A ShareTech model. Any vendor document showing the paths exist on a genuine appliance: none read. |
| How they got on | The dropper is a local installer, run after access is established, and it starts only if a flag file already exists. | What established access, what creates the flag file, or whether any flaw in either vendor's software was used. |
| Victims | The Rekoobe build was seen against South Korean targets and AVERAT deployed against Taiwanese appliances. Three relay devices in Taiwan are compromised third-party equipment, in Rapid7's assessment. | Any victim appliance by name or sector, a count, how seen or deployed was established, or a country total. |
| Who is behind it | The 2 October report refers to the threat-actor(s) and says attribution should remain an ongoing assessment. | A named actor or a confidence level for this activity. No overlap with any named covert network was found. |
| Persistence | Payloads run from memory. Rapid7 infers that the appliance's add-on package start-up very likely relaunches the dropper at boot. | A vendor document confirming that start-up behaviour: none read. |
| UK exposure | Telecommunications and network-edge operators are most affected, with no country given. | Any UK victim, customer or deployment of either product. |
Two clusters, one trick
Rapid7's own summary is that each sample "is aware of the vendor's software running on the targeted systems and implements process spoofing accordingly". The two clusters do it differently.
South Korea cluster, five hashes. Two BPFdoor builds write a PID file named for SpamSniper, a Korean anti-spam product, and rotate through ten Linux daemon names, among them chronyd, rsyslogd, crond, NetworkManager and polkitd. Two more BPFdoor builds, which Rapid7 calls data plane builds, take a process name, ora_ppmond, that Rapid7 says reads as legitimate only on hosts running Oracle-backed telecom subscriber and provisioning platforms; one of the two also copies product-style paths. The fifth hash is a Rekoobe build. It watches port 25 traffic with a kernel packet filter, borrows process names that Rapid7 labels as the SpamSniper platform's cron, web server and SMTP daemons, and its reverse shell calls out on port 25 under the name of a mail blocklist daemon. Rapid7 calls this "consistent with targeting a Korean mail or telecom environment". That is an inference from what the malware copies. The report does not describe where the samples came from.
Taiwan cluster, seven hashes. A dropper and six builds of AVERAT, a modular implant. Rapid7's heading says the dropper was "likely built for ShareTech appliances". The details that point that way are an encryption key derived from the string ShareTech, a staging directory on what Rapid7 calls the appliance's bulk storage mount, and a copy source in what it calls the appliance's own add-on package directory (my reading; Rapid7 does not set out its reasons). I could find no vendor document describing either path, so those are Rapid7's characterisations. The dropper does nothing unless a flag file already exists. It then copies two payloads into the system directory as ntpdate and udevds, starts them and deletes both files after ten seconds. One payload is the dropper itself, which becomes a watchdog. The other is AVERAT.
AVERAT calls out on port 25, opens with an SMTP greeting and a request to switch to TLS, then runs its own encrypted session. It checks in every 600 to 699 seconds with host name, user, operating system version, network interfaces and logged-in users. Its commands include file transfer, process listing and killing, up to ten concurrent shells, proxying and loading extra modules. Rapid7's reason for the port is that outbound SMTP to arbitrary mail servers is a mail gateway's core function, so "the traffic is indistinguishable from legitimate work in flow records".
Three builds call out to addresses and three to attacker-registered domains. Rapid7 says the three addresses recovered from the configurations are compromised third-party equipment rather than operator assets, in three Taiwanese cities: a network-attached storage unit, a small-business broadband appliance and a CCTV recorder. All three run a remote-access (PPTP) service with an identical banner, which Rapid7 assesses the operator installed. Rapid7 says this matches the device class that CISA, the NCSC and partners described in their April 2026 advisory AA26-113A, and that it "found no infrastructure or indicator overlap with any specific named ORB network". The advisory itself says covert networks "mostly consist of compromised SOHO routers" and also draw in other vulnerable devices, naming web cameras, video recorders, firewalls and NAS units in one botnet. "Consistent with the device class" is the strongest claim Rapid7 makes, and it is not membership of any known network.
A name is a label, six times over
When an administrator decides that an appliance is behaving, six things do the work: the process name, the PID file, the service name, the allowed port, the parent process and where the program came from. The first four are labels. Rapid7's report documents implants built to match each of them. The assumption they exploit is the one most operators hold by default: it is the mail security appliance, so what runs on it is the mail security appliance.
This is a habit of the lineage, not a one-off. BPFdoor is not new: Elastic wrote in July 2022 that the payload had been observed "across the last 5 years", which would put its earliest samples around 2017 (derived), and Rapid7 dates broad public attention to around 2021 and the source code leak to 2022. What changes is the tailoring. In its 26 March 2026 report Rapid7 described BPFdoor samples that set the process name hpasmlited and wrote a matching PID file, imitating HPE's management agent on ProLiant servers, and others that copied a Docker daemon's command line. In its 2 April post, updated on 23 September, a variant took the name cmathreshd with realistic flags, looked for the genuine agent's lock file and, if found, killed the real HPE agent and took its place. A build that kills the real thing and wears its name is the plainest case that a name proves nothing.
The diagram has a deliberate limit. Rapid7 does not describe the genuine appliance's parent process, package origin or use of packet sockets, so the genuine side of those rows is empty. You cannot compare against a baseline you do not hold. One caution on the last rows: the Taiwan payloads are staged in what Rapid7 calls the appliance's own add-on package directory, so a directory name alone does not clear a file. Ask what installed it and what started the process. A Rapid7 vice president, quoted by Dark Reading, makes the same point from the other side: "Many organizations also lack a baseline of what normal outbound mail traffic from their appliances looks like." The same interviewee also describes the boxes as "closed, vendor-managed boxes that typically can't run endpoint detection and response". Those are one vendor's views, given to a news outlet, and not in Rapid7's post. They fit the report's own detail: on a closed appliance you are left with what the vendor will let you see.
Whose assessment is it?
Dark Reading writes that BPFdoor's "Chinese handlers" keep spying on telecoms. Here is who actually says what, and with what stated confidence.
Attribution claims around the report, by who makes them. Sources: Rapid7 posts of 26 March and 2 October 2026, Trend Micro 14 April 2025, Dark Reading 2 October 2026.
- Claim
- BPFdoor belongs to a China-nexus actor, Red Menshen
- Whose it is
- Rapid7 Labs, 26 March 2026. Earlier, PwC (via Elastic, 2022) and Trend Micro (as Earth Bluecrow, 14 April 2025).
- Confidence and caveat
- Rapid7 states no confidence level. Trend Micro says medium. Rapid7 says the source code reportedly leaked in 2022, so a family name is not an actor name.
- Claim
- These SpamSniper and ShareTech samples are that actor's
- Whose it is
- Nobody, on the record read
- Confidence and caveat
- The 2 October report says the threat-actor(s) and that attribution should remain an ongoing assessment.
- Claim
- The AVERAT relays are part of a China-nexus covert network
- Whose it is
- Rapid7: consistent with the device class in AA26-113A
- Confidence and caveat
- No overlap with any named network found. Consistent with is not membership.
- Claim
- Its Chinese handlers keep spying on telecoms
- Whose it is
- Dark Reading's sentence
- Confidence and caveat
- A citation of earlier work. It is not in Rapid7's 2 October report.
| Claim | Whose it is | Confidence and caveat |
|---|---|---|
| BPFdoor belongs to a China-nexus actor, Red Menshen | Rapid7 Labs, 26 March 2026. Earlier, PwC (via Elastic, 2022) and Trend Micro (as Earth Bluecrow, 14 April 2025). | Rapid7 states no confidence level. Trend Micro says medium. Rapid7 says the source code reportedly leaked in 2022, so a family name is not an actor name. |
| These SpamSniper and ShareTech samples are that actor's | Nobody, on the record read | The 2 October report says the threat-actor(s) and that attribution should remain an ongoing assessment. |
| The AVERAT relays are part of a China-nexus covert network | Rapid7: consistent with the device class in AA26-113A | No overlap with any named network found. Consistent with is not membership. |
| Its Chinese handlers keep spying on telecoms | Dark Reading's sentence | A citation of earlier work. It is not in Rapid7's 2 October report. |
Trend Micro's own wording shows why the caveat matters. It attributed a 2025 campaign to Earth Bluecrow with "medium confidence", and added that since the BPFdoor source code was leaked in 2022, no other campaigns could be attributed to that group yet. A leaked tool is available to anyone. That is method, not accusation: the family name tells you the tooling, and a separate argument is needed to name the operator.
Rapid7 also has a commercial interest, which is not a charge against the work. It published on the day it launched Rapid7 Intelligence, and the launch press release calls this finding "a concrete illustration" of the new unit and says the malware is "actively targeting telecom and network-edge devices", which is stronger than the blog's own wording. YARA rules and more indicators sit in the customer-only Intelligence Hub, so the public list is the blog's tables. The public Rapid7 Labs GitHub indicator file for BPFdoor last changed on 2 April 2026 and contains none of the 12 hashes (checked 4 October). The sample-level detail is specific and checkable, which is what a commercial interest should be held to. Read the press release as marketing and the blog's narrower language as the claim.
What the genuine software is, and the 6,000 figure
The legitimate products named, in their makers' and distributors' own words, read on 4 October 2026 unless dated otherwise.
- Product
- SpamSniper (Jiran Group; sold in Korea by Jiran Security)
- What its maker or distributor says
- An email security product that Jiran calls Korea's leading solution, number one by market share. Sold in Japan as an appliance and a virtual appliance. A SaaS edition passed the Korean public cloud certification in June 2025.
- Where read
- global.jiran.com/spamsniper; JSecurity listing on IPROS (stamped 10 July 2023); ZDNet Korea, 17 June 2025
- Product
- ShareTech mail server, MS Series
- What its maker or distributor says
- Taichung-based vendor, founded 1999. The MS Series covers hardware and software mail servers; seven of the eight hardware models on its Chinese-language page are 1U rack-mounted, and the software edition runs in a virtual machine.
- Where read
- sharetech.com.tw overview and mail server pages
| Product | What its maker or distributor says | Where read |
|---|---|---|
| SpamSniper (Jiran Group; sold in Korea by Jiran Security) | An email security product that Jiran calls Korea's leading solution, number one by market share. Sold in Japan as an appliance and a virtual appliance. A SaaS edition passed the Korean public cloud certification in June 2025. | global.jiran.com/spamsniper; JSecurity listing on IPROS (stamped 10 July 2023); ZDNet Korea, 17 June 2025 |
| ShareTech mail server, MS Series | Taichung-based vendor, founded 1999. The MS Series covers hardware and software mail servers; seven of the eight hardware models on its Chinese-language page are 1U rack-mounted, and the software edition runs in a virtual machine. | sharetech.com.tw overview and mail server pages |
Rapid7 names the vendor ShareTech but no model, so the MS Series is the nearest match on the vendor's pages, not a finding. Rapid7 also does not name Jiran at all: it says SpamSniper is "a Korean anti-spam product" used mainly in South Korea.
The 6,000 figure. Dark Reading says SpamSniper "was used by more than 6,000 organizations as of July 2023", citing the Japanese business listing site IPROS. The sentence on IPROS is part of the company profile of JSecurity, the Japanese company that took over Jiran Soft Japan's business in January 2018. It says SPAMSNIPER has more than 6,000 adopting companies, in Japanese: 導入企業6,000社を超える. The page is stamped 10 July 2023, which is 1,182 days, about 3.2 years, before 4 October 2026 (derived). So it is a distributor's marketing line with no split by country, and it is not Rapid7's number; Rapid7 gives no count at all. It says nothing about how many of those are appliances still in service, or how many are in Korea.
Public vulnerabilities. NVD's keyword search on 4 October returns one record for SpamSniper and none for ShareTech. CVE-2020-7845 is a stack-based buffer overflow in how versions 5.0 to 5.2.7 parse the MAIL FROM command, published on 27 December 2020 from the Korean CERT, scored 8.1 by that CERT and 9.8 by NVD. Rapid7 cites neither it nor any other flaw, and nothing links the record to this activity. It is a reason to ask a vendor about patch status, not a finding.
The UK position
Nothing in Rapid7's report names the UK. ShareTech's partner page, read on 4 October, lists nine regions (Taiwan, China and Hong Kong, Thailand, Indonesia, Vietnam, Libya, Kenya, India and Poland) and none in the UK, and Jiran's global SpamSniper page makes no UK claim. A partner list is a marketing page and not an install base, so this is weak evidence of absence at most. The reason for a UK reader to care is the technique, which transfers to any closed Linux appliance on a mail path or network edge from any vendor (my generalisation; Rapid7 documents only the products and the telecom platform class named above).
Telecoms. Rapid7 says telecommunications and network-edge operators are most affected, and one BPFdoor build is dressed for Oracle-backed subscriber and provisioning platforms. For a UK public telecoms provider, the duty that bites is Regulation 6 of the Electronic Communications (Security Measures) Regulations 2022: appropriate and proportionate monitoring and analysis of security critical functions, and investigation of anomalous activity. The Telecommunications Security Code of Practice, version 1.1 of 14 July 2026, says inadequate logging and monitoring coverage "will fundamentally limit the ability to identify" anomalous activity. Whether a mail gateway or a provisioning platform is a security critical function is for each provider's own risk assessment. Neither Rapid7 nor the Code says it is.
Anyone who owns such a box. The NCSC's guidance for producers of network devices and appliances, published on 4 February 2025, says devices should support collecting "process information including parent/child relationships and arguments", process memory maps, the files and sockets each process holds, and full non-volatile storage. In July 2026 the NCSC wrote that forensic observability means giving defenders reliable ways to learn "whether it can still be trusted after an incident". Those are the capabilities the hunt list below needs. A closed appliance that offers none leaves you reading the implant's disguise at face value. The April 2026 advisory AA26-113A, issued by CISA and the NCSC with partners, asks for the same discipline at the network edge: map edge devices, baseline normal connections and keep logs.
This site has covered the same edge from other angles. FortiMail's exploited flaw with no fixed build is a different story about a different mail appliance, with a known flaw and no connection to Rapid7's report. LevelBlue's fourth NetScaler web shell disguise is another case of malware that worked because it looked like the product. See also NetScaler exploited before the patch, Zimbra, MikroTik and Cisco SD-WAN.
What to do, in the order worth doing it
Take this with you
UK organisations running closed Linux appliances on a mail path or network edge
- List every closed Linux appliance on your mail path and network edge: vendor, model, firmware, support status, who can log in, and which network can reach its management interface.
- Ask each vendor, in writing, for its supported way to verify the appliance image and to collect running processes, memory and storage evidence. NCSC guidance for device producers sets that expectation. Record the answer, including none.
- Take a baseline of a known-good appliance before anything changes: files in the system and add-on directories, services, listening ports, the process tree with parent and executable path for each process, and where each program came from. Store it off the appliance.
- Compare processes by path, owner, parent and package origin, never by name. A process wearing a product daemon's name but running from somewhere the product does not install, or started by a shell script, is the finding.
- Look for processes whose executable has been deleted, and for executable memory with no file behind it. Rapid7 says file-based checks of these appliances are unlikely to find the implants.
- Look for raw packet sockets and kernel packet filters on any host with no reason to capture packets, such as a mail gateway or a provisioning server. Ask the vendor whether the product needs one.
- Record where the appliance sends mail and why. Alert on outbound port 25 connections from anything that is not the mail service, and on mail destinations whose hostnames resolve to consumer broadband, NAS or CCTV equipment.
- Keep integrity checks, logs and DNS history somewhere the appliance cannot rewrite. Evidence held only on the box is evidence you hold on trust.
- Limit management access to a segregated management network, and watch network file shares that would let an adjacent host write programs onto an appliance, which Rapid7 lists in its mitigation advice.
- Search whatever history you hold for Rapid7's published artefacts: the 12 hashes, the three domains, the staging directory, the shell script with a php extension and the hidden state files. Treat a hit as an incident: preserve process arguments, open files, sockets and DNS history before any reboot, and tell the vendor and the NCSC.
- If you are a public telecoms provider, check whether any such appliance is, or sits beside, a security critical function under Regulation 6, and whether your monitoring would see this behaviour.
The question that exposes the gap
Every step above comes down to the one thing the report cannot do for you. Rapid7 can say what the implants copy. It cannot say what your appliance is running.
So the question is this: which of the processes running on your mail security appliance today can you show, from a record the appliance cannot edit, that the vendor installed, without trusting the name?
Key facts
Sources
- PrimarySMTP is the key: BPFDoor and AVERAT hitting the network edge, 2 October 2026. The primary report: samples, tables 7 and 8, detection guidance, attribution wordingRapid7 Intelligenceaccessed 2026-10-04
- PrimaryBPFdoor in Telecom Networks: Sleeper Cells in the Backbone, 26 March 2026. Red Menshen attribution, hpasmlited and Docker imitation, 2021 and 2022 historyRapid7 Labsaccessed 2026-10-04
- PrimaryNew Whitepaper: Stealthy BPFDoor Variants are a Needle That Looks Like Hay, 2 April 2026, updated 23 September 2026. cmathreshd imitation of the HPE agent; the whitepaper PDF itself was not downloadedRapid7 Labsaccessed 2026-10-04
- PrimaryPress release, 2 October 2026, launching Rapid7 Intelligence and presenting this finding as an illustration; used for commercial contextRapid7accessed 2026-10-04
- PrimaryBPFDoor folder: public indicator file last changed 2 April 2026 and detection script README; checked for the 12 October hashes (none present)Rapid7 Labs on GitHubaccessed 2026-10-04
- PrimarySpamSniper product page, rendered in a browser: what the legitimate product is and its market-share claimJiran Groupaccessed 2026-10-04
- PrimaryShareTech overview: Taichung-based, founded 1999, MS Series mail serversShareTech Informationaccessed 2026-10-04
- PrimaryMS Series mail server product page (Traditional Chinese content): eight hardware models, seven 1U rack-mounted, software edition on a virtual machineShareTech Informationaccessed 2026-10-04
- PrimaryGlobal locations page: nine locations listed, none in the UKShareTech Informationaccessed 2026-10-04
- PrimaryCVE-2020-7845, the only SpamSniper record returned by NVD keyword search on 4 October 2026NIST NVDaccessed 2026-10-04
- PrimaryAA26-113A, Defending Against China-Nexus Covert Networks of Compromised Devices, 23 April 2026; checked against Rapid7's description of the device classCISA, NCSC-UK and partnersaccessed 2026-10-04
- PrimaryGuidance on digital forensics and protective monitoring specifications for producers of network devices and appliances, 4 February 2025NCSCaccessed 2026-10-04
- PrimaryMaking forensic observability the norm for network devices, 29 July 2026NCSCaccessed 2026-10-04
- PrimaryRevised Telecommunications Security Code of Practice 2026, version 1.1, 14 July 2026: Regulation 6 monitoring and analysisDSIT and DCMSaccessed 2026-10-04
- PrimaryBPFDoor's Hidden Controller, 14 April 2025: Earth Bluecrow attribution with medium confidence, and the 2022 source leakTrend Microaccessed 2026-10-04
- PrimaryA peek behind the BPFDoor, 13 July 2022: payload observed across five years; PwC's 2021 discovery and Red Menshen attributionElastic Security Labsaccessed 2026-10-04
- Reported byMalicious Linux Implants Mimic Asian Mail Security Products, 2 October 2026. The news pointer; read in a browser; quotes from a Rapid7 vice presidentDark Readingaccessed 2026-10-04
- Reported bySPAMSNIPER listing stamped 10 July 2023 and JSecurity company profile with the 6,000 adopting companies line; appliance and virtual appliance formsIPROS, for JSecurityaccessed 2026-10-04
- Reported byJiran Security's SpamSniper becomes the first Korean mail security product with CSAP SaaS standard grade, 17 June 2025ZDNet Koreaaccessed 2026-10-04


