BPFDoor waits silently in the kernel for a magic packet - no open ports, no beacons, invisible to netstat. https://intel.threadlinqs.com/threat/TL-2026-3097 #ThreatIntel #BPFDoor #AVERAT #HTTPShell

BPFDoor waits silently in the kernel for a magic packet - no open ports, no beacons, invisible to netstat. https://intel.threadlinqs.com/threat/TL-2026-3097 #ThreatIntel #BPFDoor #AVERAT #HTTPShell
Rapid7 found BPFDoor and Rekoobe variants on telecom equipment in South Korea, and AVERAT on ShareTech devices in Taiwan.
Some malware posed a…
Linux backdoors now impersonate email security tools like SpamSniper & ShareTech to evade detection. #Cybersecurity #Linux #Malware #EmailSecurity #BPFDoor #AVERAT thedailytechfeed.com/linux-backdo...
A new BPFDoor backdoor variant and the AVERAT implant hide on telecom edge devices by posing as mail traffic. See how they work and how to hunt them.
#BPFDoor #AVERAT #Linux #Telecom #NetworkEdge #ORB #Rapid7 #CyberSecurity
New Linux implants pose as mail security appliances and hide C2 in SMTP on port 25. https://intel.threadlinqs.com/threat/TL-2026-2875 #ThreatIntel #BPFDoor #Rekoobe #AVERAT
SMTP port 25 is being abused by BPFDoor, BPF Rekoobe, and AVERAT to blend into telecom and appliance networks with BPF filters and fileless staging. South Korea, Taiwan, and edge devices were hit. #SouthKorea #BPFDoor #AVERAT