Linux Malware Mimicked Asian Email Security Appliances
Attackers are masking malicious implants as trusted email gateways to gain persistent, undetected access to networks.
Updated on Oct. 2, 2026 in Cybersecurity

Live Poll
Do you trust the security of the network appliances used by your workplace?
Security researchers have documented multiple Linux-based malware campaigns that disguise malicious tools as established email security appliances. These implants target organizations in Asia and beyond by masquerading as software used to filter enterprise communications.
Why it matters
Secure email gateways act as critical chokepoints between the public internet and private networks, often operating without the oversight of standard endpoint security software. By mimicking these appliances, attackers secure an advantageous position to intercept traffic and maintain persistence.
The AVERAT remote access Trojan and BPFdoor variants utilize TCP Port 25, the standard port for SMTP email traffic, to blend command-and-control communication with legitimate enterprise activity. The AVERAT dropper employs a 10-second delay before deleting its malicious files, a tactic designed to avoid leaving forensic traces.
The players
Rapid7
A cybersecurity firm specializing in vulnerability management, threat intelligence, and analytics software.
The details
The attackers are exploiting the trusted status of appliances such as the SpamSniper anti-spam software and ShareTech information appliances. By masquerading as these services, the malware implants, including BPFdoor and Rekoobe, can execute arbitrary commands while appearing as normal network traffic. The AVERAT dropper functions by installing the necessary malicious programs and then systematically deleting the installation binaries while keeping the compromised processes active in the system's memory.
Timeline
July 2023: SpamSniper usage reached over 6,000 organizations.
May 2026: Rapid7 documented new techniques for BPFdoor propagation.
October 2026: Researchers reported the discovery of these appliance-mimicking campaigns.
The Tech Race
This campaign represents a shift toward exploiting the architectural blind spots inherent in specialized security hardware. By focusing on the gaps between internet-facing appliances and internal endpoint security, these attackers are outpacing conventional detection methods that rely on monitoring standard server operating systems.
Enterprises relying on SpamSniper or ShareTech appliances should immediately audit their network logs for anomalous traffic occurring over TCP Port 25. Administrators must ensure these appliances are isolated from sensitive core network segments and are subject to the same egress filtering policies as standard workstations.
The takeaway
The move to mimic trusted security infrastructure demonstrates that attackers are increasingly prioritizing the exploitation of blind spots in network configuration. Organizations should evaluate whether their email gateways are operating with excessive privileges and monitor for unexpected traffic patterns emerging from these specific security nodes.
Further reading
For broader trends in network defense and threat intelligence, visit our Cybersecurity section.
Source note: This article includes information reported by Dark Reading.
Live Poll
Do you trust the security of the network appliances used by your workplace?







