
BPFDoor variants impersonate SpamSniper PID files and Oracle PMON processes against Korean and Taiwanese telecom edges
Linux backdoors targeting telecom appliances in Korea and Taiwan now impersonate SpamSniper and Oracle processes while routing triggers through HTTPS and SMTP. The activity updates BPFDoor and introduces AVERAT, showing rapid retooling after public signatures. Attribution remains behavioral; no new technical IOCs tie the campaigns to state actors beyond prior reporting.
The samples rotate ten daemon names while binding to port 25 traffic and using BPF to trigger only on magic packets wrapped in HTTPS POSTs after SSL offload. One variant sets its PID file to match Jiran Group's SpamSniper, while another adopts ora_ppmond to mimic Oracle subscriber platforms. A separate Rekoobe-derived loader and the AVERAT dropper both route C2 over SMTP, confirming modular reuse of TinyShell for upload and interactive sessions.
Red Menshen (also tracked as Earth Bluecrow) has maintained this pattern since 2021 across Middle East and Asia telecoms. The shift from static Layer-4 signatures to edge-proxy HTTPS and legitimate email product names shows direct adaptation to public Suricata rules published after earlier disclosures. Overlap with Liminal Panda and UNC3886 TinyShell usage suggests either shared tooling or parallel operations against the same infrastructure layer.
Contract records and procurement filings from Korean and Taiwanese carriers indicate continued reliance on legacy edge devices with minimal process attestation, creating persistent blind spots. No independent packet captures have yet confirmed the claimed Red Menshen attribution beyond behavioral similarity.
Operators are expected to extend the HTTPS-wrapped trigger and SMTP C2 pattern to additional APAC carriers; defenders should baseline legitimate SpamSniper and Oracle PMON process trees on appliances rather than relying on name alone.
Red Menshen: Additional carrier edge devices in Japan or Singapore show identical SpamSniper PID spoofing within 120 days
Sources (2)
- [1]Rapid7 BPFDoor Analysis(https://www.rapid7.com/blog/post/2024/03/12/bpfdoor-linux-backdoor/)
- [2]Jiran SpamSniper Product Documentation(https://www.jiran.com/products/spamsniper)