Rapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a newly observed BPFDoor variant, a BPF Rekoobe build seen against South Korean targets, a dropper, and six builds of a Linux implant Rapid7 researchers track as AVERAT, deployed against Taiwanese appliances. Additionally, researchers provide source code details of the Rapid7 BPFDoor controller introduced in our April 2026 blog, Stealthy BPFDoor Variants are a Needle That Looks Like Hay.
The chain uses two binaries. A dropper writes a shell script to the appliance’s storage mount and executes it. The script stages both payloads into /sbin under the names ntpdate and udevds, launches them, and deletes each file ten seconds later while the processes continue running. One of those payloads is the dropper itself, re-executing as a resident watchdog, leaving both processes running without an on-disk image.
Read more…
Source: Rapid7 News
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure with Malicious Distributed Systems
August 26, 2026
The Federal Bureau of Investigation, National Security Agency, and Cyber National Mission Force are releasing this joint cybersecurity advisory to alert organizations concerning China-linked cyber threat actors, who use the acronyms QTFY, QT, and QTCYBER for themselves and their tools and have developed malicious distributed platforms to compromise the networks of US and foreign organizations. ...
- Medical device maker Boston Scientific says a cyberattack is causing a ‘global disruption’ to its operations
August 26, 2026
A cyberattack on U.S. medical device maker Boston Scientific is causing an ongoing “global disruption” to its operations, according to a federal regulatory filing on Wednesday. This is the latest health tech giant to face a cyberattack in recent weeks. The Massachusetts-based company, which makes medically implanted devices like pacemakers and defibrillators, confirmed in a filing with the ...
- ShinyHunters and ReliaQuest trade blows over claimed breach
August 24, 2026
ShinyHunters has claimed another cybersecurity scalp, but ReliaQuest says the crew’s social engineering attack only got as far as one employee identity before its defenses slammed the door. The ransomware baddies listed US-based infosec biz ReliaQuest on its leak site on August 23, claiming the corporation as its latest victim. The listing, seen by The Register, links to ...
- Experts warn 2,000 hacked WordPress sites were secretly running a global crime ring
August 22, 2026
Check Point Research has unearthed a global cybercrime ring that relied on a network of WordPress websites. The investigation into an operation dubbed “StopAndProtect” found a network of 5,000 infected computers around the globe, and 2,000 WordPress domains. WordPress currently provides content management for around 43% of websites worldwide, making it the most significant CMS available. ...
- Private equity firm Apollo confirms data breach amid hacking wave targeting financial giants
August 21, 2026
Private equity giant Apollo Global Management has confirmed a data breach in which hackers stole reams of personal information from the company’s cloud systems. The breach comes a month after security researchers sounded the alarm on a new hacking campaign targeting financial and private equity giants. The financial giant confirmed the incident in a letter filed with California’s ...
- Securing the overlooked corners of the Software Development Lifecycle (SDLC) supply chain
August 21, 2026
While supply chain threats have been quietly compounding over the past decade, the last 12–18 months have triggered a drastic shift in the scale and velocity of these attacks. Rather than just hunting for bugs in finished software, attackers are targeting the everyday tools and code developers rely on. Unit 42 research shows this happening at ...
