Skip to content

Security1 publisher2 min readPublished

Linux implants on Korean and Taiwanese edge appliances run from memory after erasing their files

Rapid7 tracked Linux implants on South Korean and Taiwanese edge appliances that erase their files ten seconds after launch but keep running. File scans miss them, so defenders have to hunt processes with no image on disk.

The Watch · Security desk

Illustration accompanying Linux implants on Korean and Taiwanese edge appliances run from memory after erasing their files

What happened

  • The haul spans a new BPFDoor variant, a BPF Rekoobe build against South Korean targets, a dropper, and six builds of an implant Rapid7 tracks as AVERAT on Taiwanese appliances.
  • The dropper derives its encryption key from the string ShareTech and writes itself into the appliance's own add-on package directory.
  • The South Korean BPFDoor builds pose as the PID file of SpamSniper, a Korean anti-spam product, and rotate through ten Linux daemon names.
  • One of the two staged payloads is the dropper itself, re-executing as a resident watchdog to keep the pair alive.
  • The implants run as passive BPF sockets that take no listening port, and their beacons ride ordinary DNS, TCP and SMTP traffic.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint Each build mimics the vendor software already on the box, so a hunt tuned to one site's process names does not carry to the next.
  • capability The HTTPS-wrapped trigger rides SSL offloading to reach the implant, so deep packet inspection built for Layer 4 magic bytes no longer catches it.
  • precedent The operators re-tooled once already after vendors shipped Suricata and Snort rules, so fresh signatures for this chain should be expected to age fast.
  • exposure The affected gear includes CCTV and DVR appliances that can sit close to the network core, making a compromised camera a foothold next to core systems.

Rapid7's reconstruction of the BPFDoor controller shows the trigger adapting to defenders. Older variants carried raw magic bytes such as 0x7255 or 0x5293 in TCP or UDP headers [9]. Vendors answered with static Suricata and Snort rules for those Layer 4 anomalies, so the operators shifted their aim to the edge proxies and wrapped the magic packet inside a standard HTTPS POST, riding the SSL offloading common in telecom networks [10][11].

Proxies rewrite headers in transit, adding X-Forwarded-For and changing User-Agent lengths, so the backdoor can no longer read its payload from a fixed offset [12]. The controller fixes that by sending padded, benign-looking requests such as POST /admin/login.aspx?id=99990, which forces the string 9999 to sit at offset 26 of the TCP payload every time [13]. The backdoor reads from there, scans forward to the \r\n\r\n terminator, and pulls the hex-encoded command out of the HTTP body [14]. While it runs, the controller renames itself to /usr/sbin/abrtd through PR_SET_NAME, and a #ifndef SOLARIS guard applies that disguise only where Linux prctl exists [15].

The South Korean BPFDoor variant opens a raw PF_PACKET socket with a classic BPF filter that matches Rapid7's Variant F, keyed to magic bytes 0x6693 for UDP, 0x4274 for TCP and 0x7820 for ICMP [16]. On a match it reads the sender's address and either connects back, when the password is gZbpx0, or opens a bind shell, when the password is sT21xf [17].

This work extends the BPFDoor controller Rapid7 reconstructed in an earlier post, "Stealthy BPFDoor Variants are a Needle That Looks Like Hay" [18]. On the appliances, the two staged payloads enter /sbin as ntpdate and udevds, names that look ordinary on a Linux box [2].

What to watch

  • Whether Rapid7 names the actor behind the cluster or shows what binds the six AVERAT builds.
  • Whether SpamSniper and ShareTech ship detections for the impersonated PID files and add-on directories.
  • Whether the offset-26 HTTPS trigger turns up against non-telecom edge gear once the technique is public.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories