importantSYS.SOURCE: The Hacker News• 2026-10-06T23:54:25+05:30
Linux Backdoors Mimicking Email Security Tools Target Telecoms in Korea and Taiwan
Linux backdoors are impersonating email security tools like SpamSniper and ShareTech to evade detection in South Korea and Taiwan, targeting telecom and network appliances. The malware uses techniques such as BPFDoor and AVERAT, leveraging SMTP for C2 and process spoofing to remain undetected.
Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection.
Threat actors are known to name their malicious software after a legitimate operating system component or a process as a defense evasion measure. By borrowing the name of a real binary, it may
*** END OF TRANSMISSION ***