Rapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a newly observed BPFDoor variant, a BPF Rekoobe build seen against South Korean targets, a dropper, and six builds of a Linux implant Rapid7 researchers track as AVERAT, deployed against Taiwanese appliances. Additionally, researchers provide source code details of the Rapid7 BPFDoor controller introduced in our April 2026 blog, Stealthy BPFDoor Variants are a Needle That Looks Like Hay.
The chain uses two binaries. A dropper writes a shell script to the appliance’s storage mount and executes it. The script stages both payloads into /sbin under the names ntpdate and udevds, launches them, and deletes each file ten seconds later while the processes continue running. One of those payloads is the dropper itself, re-executing as a resident watchdog, leaving both processes running without an on-disk image.
Read more…
Source: Rapid7 News
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- An inside job: The human factor of cybersecurity
September 9, 2019
As businesses continue their digital transformation, ensuring the sensitive information they handle always remains safe and secure is now a priority. However, even deploying just the latest cybersecurity applications might not enough to offer full protection. The latest research from the Telstra 2019 Security Report makes for worrying reading as it concludes 89% of cybersecurity risks are ...
- China’s APT3 Pilfers Cyberweapons from the NSA
September 6, 2019
Large portions of APT3’s remote code-execution package were likely reverse-engineered from prior attack artifacts. The advanced persistent threat (APT) group known as APT3, which researchers across the board link to the Chinese government, has built a full in-house battery of exploits and cybertools collectively dubbed “UPSynergy.” An analysis of the toolkit has uncovered a geopolitical cat-and-mouse spy ...
- Thousands of servers infected with new Lilocked (Lilu) ransomware
September 6, 2019
Thousands of web servers have been infected and had their files encrypted by a new strain of ransomware named Lilocked (or Lilu). Infections have been happening since mid-July, and have intensified in the past two weeks, ZDNet has learned. Based on current evidence, the Lilocked ransomware appears to target Linux-based systems only. First reports date to mid-July, after ...
- Malware Classification with ‘Graph Hash,’ Applied to the Orca Cyberespionage Campaign
September 6, 2019
In malware research, threat hunting and sharing of threat intelligence, such as exchanging indicators of compromise (IoCs) in the form of hashes (e.g., MD5s, SHA256s), are common industry practices and helpful for information security professionals. Researchers, for instance, would typically search for malware samples on VirusTotal using hashes. However, hashes have some characteristics that could ...
- A Chinese APT is now going after Pulse Secure and Fortinet VPN servers
September 5, 2019
A group of Chinese state-sponsored hackers is targeting enterprise VPN servers from Fortinet and Pulse Secure after details about security flaws in both products became public knowledge last month. The attacks are being carried out by a group known as APT5 (also known as Manganese), ZDNet has learned from sources familiar with the attacks. According to a ...
- Hackers exploiting popular social engineering ‘toolkits’ to refine cyber attacks
September 4, 2019
Hackers are regularly using highly customisable online resources to add social engineering components to render their attacks more effective, according to new research from Malwarebytes. One website identified by the team features an expansive toolkit that has drawn more than 100,000 visits in the past few weeks, offering design and framework support to attackers. The resource, dubbed Domen, is built ...
