SMTP is the key: BPFDoor and AVERAT hitting the network edge
What happened
The script stages both payloads into /sbin under the names ntpdate and udevds , launches them, and deletes each file ten seconds later while the processes continue running. Overview Rapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target.
A dropper writes a shell script to the appliance's storage mount and executes it. One of those payloads is the dropper itself, re-executing as a resident watchdog, leaving both processes running without an on-disk image.
The dropper derives its encryption (scrambling data so only the holder of the key can read it) key from the string ShareTech and lives in the appliance's own add-on package directory. The BPFDoor variants seen against South Korean systems impersonate the PID file of SpamSniper, a Korean anti-spam product, and rotate through ten Linux daemon names.
Sources & evidence
- Rapid7 Blog Primary / official
SMTP is the key: BPFDoor and AVERAT hitting the network edge ↗
https://www.rapid7.com/blog/post/tr-smtp-is-the-key-bpfdoor-averat-hitting-the-network-edge