On October 2, 2026, Rapid7 published an analysis describing six builds of the Linux implant AVERAT deployed against Taiwanese appliances. The analysis also covered separate BPFDoor variants and a BPF Rekoobe build observed against South Korean targets. AVERAT’s command-and-control traffic uses SMTP—the protocol commonly used to send email—over TCP port 25, a route that can blend into expected mail-gateway traffic. Rapid7’s analysis describes the malware’s communications, capabilities, and defensive indicators.
AVERAT’s reported activity in Taiwan
Rapid7 described AVERAT as a previously unreported implant and said it had analyzed six builds deployed against Taiwanese appliances. Separately, Rapid7 assessed that the analyzed dropper was likely built for ShareTech appliances. The dropper is a local installer that runs after access to a system has already been established.
The installer copies two payloads into /sbin, naming them ntpdate and udevds, and launches them. Ten seconds later, it removes the files from disk, while the processes continue running without on-disk executable images. The familiar-looking names and disappearing files make process and filesystem checks important parts of an investigation.
How AVERAT uses SMTP for command-and-control
Command-and-control, often shortened to C2, is the channel malware uses to receive instructions and report back. AVERAT connects over SMTP on TCP port 25, sends EHLO, and requests STARTTLS before beginning its own encrypted session. The analyzed builds check in every 600–699 seconds, an interval the operator can configure.
During those check-ins, AVERAT can report a device’s hostname, current user, operating-system version, network interfaces, and logged-in users. Rapid7’s analysis also describes a command set that can enumerate and traverse directories; download, upload, or delete files; list and terminate processes; change C2 settings; reboot the device; load shared objects; and open proxy or port-forwarding channels. One command supports up to ten concurrent shell sessions.
BPFDoor and BPF Rekoobe are separate findings
The South Korea-related samples use different mechanisms from AVERAT’s SMTP-based C2. Rapid7 reported that BPFDoor uses raw packet sockets and Berkeley Packet Filter (BPF) filters to detect trigger traffic. In one described variant, the trigger is wrapped in HTTPS POST requests sent through edge proxies.
The separate BPF Rekoobe sample watches TCP, UDP, and SCTP traffic over IPv4, as well as UDP over IPv6, when both source and destination ports are 25. These are distinct samples and behaviors; they are not AVERAT’s communications method.
What defenders can investigate
Rapid7 recommends checking for running processes whose /proc/<pid>/exe path points to a deleted file, unexpected raw packet sockets or BPF filters, and outbound TCP port 25 connections from processes that are not mail software. Process names that imitate familiar software are another signal to examine alongside the staging sequence: files placed under /sbin, launched, then unlinked ten seconds later.
The analysis also identifies /HDD/ms6x2xTo64/, a shell script with a .php extension, marker files, and a sequence involving shell execution, copying, and removal as artifacts to investigate. For network monitoring, Rapid7 lists mx.zxopfds.com, spam.suwaccqi.com, and mx1.wwstifsteel.com as AVERAT indicators; it gives TCP port 25 as the default C2 port.
Rapid7 also lists 59.125.211.65, 122.116.138.33, and 1.34.200.85 as compromised Taiwanese third-party CPE devices recovered from AVERAT configurations. It assesses them as relay systems, not intentional operator infrastructure.
Rapid7 lists these SHA-256 values for the analyzed files:
- Dropper:
2bedc26d4b29b435c21962beed7db21188a0219a0d28334bba8b4fb1656d7b15 - AVERAT:
bf8135f46ecedfe5bd06fcecbb2e721c2367ff765b18f4aa3f868e6597f49e47 - AVERAT:
4925bcca085ec504f51191645da278d8e96698d91f3c6df44146336c697b4de8 - AVERAT:
a4379e115d3c4420f5d4b92561022d6e0897990e7297be65c033d47de68e6a6a - AVERAT:
925c041807d4fb9dfe2ad84f963c2a4c60ea1289f6a0bdccbfb944478ffc2cf2 - AVERAT:
2fe2dd402ee6f9c578fce6dd4b36daaa407e99133e5dd502f2afca80feb60150 - AVERAT:
a65048eb30661e27f8edc2dd8d8c77ec87faec1f1750f6e04e7ecaf069a32858