Rapid7's threat research team has published new intelligence on a Linux malware set purpose-built to blend into telecommunications and network edge environments. The toolset includes a newly observed BPFDoor variant, a BPF-enabled Rekoobe build seen against South Korean targets, a dropper, and six builds of a Linux implant tracked as AVERAT deployed against Taiwanese network appliances. Alongside the malware analysis, Rapid7 released source-code details for their open BPFDoor controller — a significant development for defenders, because it gives blue teams a working instrument to validate BPF-backdoor detection in their own environments.
The attack chain is deliberately quiet: a dropper writes a shell script to the appliance's storage mount, the script stages two payloads into /sbin under the names ntpdate and udevds, executes them, and then deletes both files ten seconds later — while the processes continue running from memory. No persistent binary on disk. No cron job in the obvious places. Just two long-lived processes impersonating legitimate system daemons on appliances that most organizations never instrument.
If you operate telecom infrastructure, ISP edge gear, or Linux-based network appliances — firewalls, VPN concentrators, session border controllers, SD-WAN edges — this campaign is aimed at your perimeter. This post breaks down the tradecraft and gives you concrete detection content for Sigma, Microsoft Sentinel, and Velociraptor, plus a hardening and triage script you can run today.
Why Network Edge Appliances Are the Target
I've led multiple IR engagements where the initial foothold was a network appliance rather than an endpoint, and the pattern is always the same: edge devices are the least-monitored tier of the enterprise. They typically have:
- No EDR coverage — most appliances don't support endpoint agents, or vendors prohibit installing them.
- Weak or absent logging — syslog forwarding is often disabled, rate-limited, or never makes it to the SIEM.
- Long uptime, rare patching — appliances run for years untouched, which means a memory-resident implant survives undisturbed.
- Implicit network trust — edge devices sit at the trust boundary with privileged visibility into all ingress/egress traffic. An implant there sees everything.
The malware authors understand this intimately. Naming payloads ntpdate and udevds is not lazy opsec — it's tuned for the exact process listing a tired NOC engineer expects to see on a Linux appliance. udevds is one character away from the legitimate udevd. ntpdate is a real time-sync utility that appears transiently on virtually every Linux system. On a network appliance where nobody has a behavioral baseline, both names pass casual inspection.
Technical Analysis
The Toolset
Per Rapid7's research, the campaign's malware set comprises:
- A new BPFDoor variant — BPFDoor is a passive backdoor that leverages Berkeley Packet Filter (BPF) socket filters to activate on a "magic packet," allowing it to receive commands without holding an obvious listening socket that shows up in
netstat/ssoutput. This is why it persists for years in victim environments: it defeats the most common manual network-triage step. - A BPF Rekoobe build — Rekoobe is a Linux backdoor historically associated with espionage activity; this build adds BPF filtering and was observed targeting South Korean victims.
- A dropper — responsible for the staging chain described below.
- Six AVERAT builds — a Linux implant Rapid7 tracks as AVERAT, deployed specifically against Taiwanese network appliances.
No CVE is associated with this reporting — the initial access vector is not the story here. The story is post-compromise stealth: how these implants survive on appliances that defenders can't easily instrument.
The Staging Chain (Defender's View)
The execution flow produces a specific, observable sequence of forensic artifacts:
- Dropper execution — a binary runs on the appliance and writes a shell script to the device's storage mount (the writable partition/persistent storage path on the appliance).
- Script execution — the script stages two malicious binaries into
/sbinwith the filenamesntpdateandudevds. - Launch — both binaries are executed, typically as daemonized background processes.
- Self-cleaning — the script deletes both files ten seconds after launch. The processes keep running because their executable images are already loaded and mapped; Linux happily runs a process whose on-disk binary has been unlinked.
This "execute-then-delete" pattern is the single most valuable detection hook in the entire chain. On a healthy appliance, files in /sbin are installed by the vendor image or a package manager and essentially never churn. A binary appearing in /sbin and vanishing seconds later is anomalous by definition.
What BPFDoor's BPF Component Means for Your Detection Strategy
This matters enormously for network-based hunting. A BPF socket filter attaches at the kernel level and inspects packets before userspace networking tools see them in the conventional sense. Practically:
- There may be no listening socket visible via
ss -tlnpornetstatattributable to the implant. The backdoor activates only when a packet matching its filter arrives (the "SMTP is the key" reference in Rapid7's title reflects the magic-packet semantics — traffic that looks like ordinary mail chatter). - Outbound C2 may be triggered and short-lived, riding permitted egress ports.
- Netflow alone won't convict it — you need to correlate rare, low-volume connections from the appliance itself (not forwarded traffic) to unusual external destinations.
This is why the detection content below emphasizes process and filesystem telemetry over socket enumeration. You hunt the process that shouldn't exist, not the port you can't see.
Exploitation Status
This is confirmed in-the-wild activity against real targets: Taiwanese network appliances (AVERAT) and South Korean organizations (BPF Rekoobe), with tooling consistent with telecom-focused espionage tradecraft. There is no indication this is theoretical or lab-only. Organizations operating network edge infrastructure in or adjacent to telecom, ISP, and managed services environments should treat this as an active threat requiring proactive hunting, not a watch item.
Detection & Response
The detection strategy below is built around the three strongest observable behaviors in the chain: (1) masquerading process names in /sbin, (2) execution of binaries that have been deleted from disk, and (3) dropper/script staging activity on storage mounts.
SIGMA Rules
These rules target Linux telemetry (auditd, Sysmon for Linux, or equivalent process-creation and file-event sources). The first rule catches the masquerading binaries directly — it is deliberately narrow and should be near-zero-noise. The second catches the broader execute-then-delete technique that defines this campaign.
---
title: Suspicious Masquerading Binary in /sbin - BPFDoor AVERAT Campaign
description: Detects execution of udevds or a daemonized ntpdate from /sbin, matching the process masquerading used by the BPFDoor/AVERAT Linux implant chain against network edge appliances.
references:
- https://www.rapid7.com/blog/post/tr-smtp-is-the-key-bpfdoor-averat-hitting-the-network-edge
- https://attack.mitre.org/techniques/T1036/005/
author: Security Arsenal
date: 2026/04/28
id: 3f8a2b91-7c4e-4d1a-9b6e-2a5c8d0e1f37
status: experimental
tags:
- attack.defense_evasion
- attack.t1036.005
- attack.persistence
logsource:
category: process_creation
product: linux
detection:
selection_udevds:
Image|endswith: '/sbin/udevds'
selection_ntpdate_anomalous:
Image|endswith: '/sbin/ntpdate'
ParentImage|endswith:
- '/bin/sh'
- '/bin/bash'
- '/sbin/udevds'
condition: 1 of selection_*
falsepositives:
- Vendor appliance scripts invoking ntpdate for time sync (parent will typically be a known vendor binary or cron, not an interactive shell)
level: high
---
title: Execution of Deleted Binary on Linux - Implant Self-Cleaning Technique
description: Detects processes whose executable has been unlinked from disk after launch (execute-then-delete), the self-cleaning behavior used by BPFDoor/AVERAT droppers to remove evidence from appliance storage while the implant keeps running.
references:
- https://www.rapid7.com/blog/post/tr-smtp-is-the-key-bpfdoor-averat-hitting-the-network-edge
- https://attack.mitre.org/techniques/T1070/004/
author: Security Arsenal
date: 2026/04/28
id: 8c1d4e52-3b9f-4a78-bc60-7d2e9f41a5b8
status: experimental
tags:
- attack.defense_evasion
- attack.t1070.004
logsource:
category: process_creation
product: linux
detection:
selection:
Image|contains: ' (deleted)'
filter_known_updaters:
Image|startswith:
- '/usr/lib/snapd/'
- '/var/lib/dpkg/'
condition: selection and not 1 of filter_*
falsepositives:
- Package managers and runtime updaters transiently running replaced binaries during system updates
level: high
---
title: Shell Script Staging Binaries into /sbin on Network Appliance
description: Detects shell interpreters copying, moving, or writing executable content into /sbin, consistent with the dropper script that stages ntpdate and udevds implants into the system binary path.
references:
- https://www.rapid7.com/blog/post/tr-smtp-is-the-key-bpfdoor-averat-hitting-the-network-edge
- https://attack.mitre.org/techniques/T1059/004/
author: Security Arsenal
date: 2026/04/28
id: b47e0f63-1a2c-4d95-8e31-9f04b7c26d19
status: experimental
tags:
- attack.execution
- attack.t1059.004
- attack.defense_evasion
logsource:
category: process_creation
product: linux
detection:
selection_shell:
Image|endswith:
- '/sh'
- '/bash'
- '/dash'
- '/busybox'
selection_action:
CommandLine|contains:
- 'cp '
- 'mv '
- 'install '
- 'cat >'
- 'dd '
selection_target:
CommandLine|contains:
- '/sbin/ntpdate'
- '/sbin/udevds'
condition: selection_shell and (selection_action or selection_target)
falsepositives:
- Legitimate vendor firmware installation scripts (correlate with maintenance windows and change tickets)
level: critical
Microsoft Sentinel / Defender KQL
Even though these are Linux appliances, most MSSP and enterprise SOCs ingest appliance syslog and auditd output into Sentinel via CEF/Syslog forwarders — which is exactly why edge-device log forwarding matters. This query hunts the process-name masquerading and the deleted-binary artifact in Syslog data, and additionally correlates rare outbound connections sourced from the appliance itself (BPFDoor-style implants generate low-volume egress that hides among forwarded traffic).
// Hunt: BPFDoor / AVERAT masquerading processes and deleted-binary execution in Linux syslog
// Requires: Syslog or CommonSecurityLog ingestion from edge appliances (auditd execve/process events)
let Lookback = 14d;
let SuspiciousNames = dynamic(["udevds", "sbin/ntpdate"]);
let ProcessHits =
Syslog
| where TimeGenerated > ago(Lookback)
| where ProcessName in~ (SuspiciousNames)
or SyslogMessage has_any ("/sbin/udevds", "/sbin/ntpdate", "(deleted)")
| extend Indicator = case(
SyslogMessage has "(deleted)", "Deleted binary execution",
SyslogMessage has "/sbin/udevds", "udevds masquerade",
SyslogMessage has "/sbin/ntpdate", "ntpdate masquerade",
"Process name match")
| project TimeGenerated, Computer, ProcessName, SyslogMessage, Indicator;
ProcessHits
| union (
// Outbound connections sourced FROM the appliance itself (not forwarded traffic)
// BPFDoor-style implants produce rare, low-volume egress to unusual destinations
CommonSecurityLog
| where TimeGenerated > ago(Lookback)
| where DeviceVendor has_any ("linux", "unix") or isnotempty(SourceHostName)
| summarize ConnectionCount = count(), DistinctDestinations = dcount(DestinationIP),
Destinations = make_set(DestinationIP, 20), Ports = make_set(DestinationPort, 20)
by SourceIP, SourceHostName, bin(TimeGenerated, 1d)
| where ConnectionCount < 25 and DistinctDestinations between (1 .. 5)
)
| sort by TimeGenerated desc
Tune the egress correlation block against your appliance baseline — the intent is to surface devices that speak to almost nobody, suddenly speaking to one or two external IPs. On an edge appliance, the device itself should almost never initiate internet-bound sessions outside NTP, DNS resolvers you control, and vendor update endpoints. Alert on anything outside that allowlist.
Velociraptor VQL
For appliances where you can deploy a collector (or acquire via SSH during IR), Velociraptor is the right tool for finding what netstat can't: processes running from deleted executables, masquerading binaries, and the BPF programs BPFDoor depends on.
-- Security Arsenal Hunt: BPFDoor / AVERAT artifacts on Linux edge appliances
-- Looks for: masquerading /sbin binaries, processes running from deleted
-- executables, and loaded BPF programs (BPFDoor's socket-filter mechanism)
-- 1) Processes whose on-disk binary has been deleted (execute-then-delete)
LET deleted_procs = SELECT Pid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE Exe =~ '(deleted)'
OR Name =~ '^(udevds|ntpdate)$'
-- 2) /sbin contents with mtimes -- masquerading binaries that reappear
-- (attackers sometimes restage) stand out against a vendor-frozen /sbin
LET sbin_listing = SELECT FullPath, Mtime, Size, Mode
FROM glob(globs='/sbin/*')
WHERE FullPath =~ '(udevds|ntpdate)$'
OR Mtime > now() - (30 * 24 * 3600) -- anything modified in last 30 days
-- 3) Loaded BPF programs and maps -- BPFDoor requires an attached BPF filter.
-- A healthy appliance typically has ZERO loaded BPF programs.
LET bpf_progs = SELECT FullPath, Data
FROM glob(globs='/sys/fs/bpf/**', accessor='file')
SELECT 'deleted_or_masquerading_process' AS ArtifactType,
Pid AS _Pid, Name AS _Name, Exe AS _Path,
CommandLine AS _Detail, CreateTime AS _Time
FROM deleted_procs
UNION ALL
SELECT 'sbin_recent_modification', NULL, NULL, FullPath,
format(format='size=%v mode=%v', args=[Size, Mode]), Mtime
FROM sbin_listing
Two operational notes on the VQL: first, on a vendor-locked appliance, any recently modified file in /sbin deserves scrutiny — that directory should be frozen at firmware build time. Second, enumerate BPF state directly during a live response with bpftool prog list and bpftool map list — on a clean appliance this output should be empty or near-empty, and an unexpected socket-filter program attached to a raw packet interface is a strong BPFDoor indicator.
Rapid Triage / Hardening Script
Run this on any Linux edge appliance or Linux host in scope. It checks for the specific indicators from this campaign — masquerading processes, deleted running binaries, anomalous /sbin state, loaded BPF programs, and suspicious egress listeners — and optionally applies detective hardening via auditd.
#!/bin/bash
# Security Arsenal - BPFDoor/AVERAT edge appliance triage & hardening
# Run as root. Safe read-only checks by default; pass --harden to add audit rules.
echo "=== [1] Processes named udevds / ntpdate (masquerade check) ==="
ps -eo pid,ppid,user,lstart,comm,args | grep -E '[u]devds|[n]tpdate' || echo " none found"
echo ""
echo "=== [2] Processes running from DELETED binaries (execute-then-delete) ==="
found=0
for pid in $(ls /proc | grep -E '^[0-9]+$'); do
target=$(readlink "/proc/$pid/exe" 2>/dev/null)
if [[ "$target" == *"(deleted)"* ]]; then
echo " ALERT: PID $pid ($(cat /proc/$pid/comm 2>/dev/null)) -> $target"
found=1
fi
done
[[ $found -eq 0 ]] && echo " none found"
echo ""
echo "=== [3] /sbin integrity: udevds present? ntpdate present? recently modified files? ==="
ls -la /sbin/udevds /sbin/ntpdate 2>/dev/null || echo " masquerade filenames not on disk (expected if cleaned)"
find /sbin -type f -mtime -30 -exec ls -la {} \; 2>/dev/null || true
echo ""
echo "=== [4] Storage mounts - look for stray scripts (dropper staging ground) ==="
mount | grep -E 'media|mnt|storage|flash' || true
find /mnt /media -maxdepth 3 -name '*.sh' -mtime -60 2>/dev/null || true
echo ""
echo "=== [5] BPF programs/maps (BPFDoor requires an attached BPF filter) ==="
if command -v bpftool >/dev/null 2>&1; then
bpftool prog list; bpftool map list; bpftool link list
else
echo " bpftool not installed - check /sys/fs/bpf manually:"
ls -laR /sys/fs/bpf 2>/dev/null || echo " no bpf fs mounted"
fi
echo ""
echo "=== [6] Device-sourced egress (device itself should rarely initiate outbound) ==="
ss -tnp state established 2>/dev/null | head -50 || netstat -tnp 2>/dev/null | head -50
echo ""
echo "=== [7] Cron / init / rc persistence review ==="
crontab -l 2>/dev/null; ls -la /etc/cron.* 2>/dev/null
grep -rEl 'udevds|sbin/ntpdate' /etc/init.d /etc/rc* /etc/systemd 2>/dev/null || echo " no references in init/systemd"
if [[ "$1" == "--harden" ]]; then
echo ""
echo "=== [HARDEN] Installing auditd watch rules for /sbin writes + execve ==="
if command -v auditctl >/dev/null 2>&1; then
auditctl -w /sbin -p wa -k sbin_integrity
auditctl -a always,exit -F arch=b64 -S execve -F exe=/sbin/udevds -k implant_exec
auditctl -a always,exit -F arch=b64 -S execve -F exe=/sbin/ntpdate -k implant_exec
cat >> /etc/audit/rules.d/edge-implant.rules <<'EOF'
-w /sbin -p wa -k sbin_integrity
-a always,exit -F arch=b64 -S execve -F exe=/sbin/udevds -k implant_exec
-a always,exit -F arch=b64 -S execve -F exe=/sbin/ntpdate -k implant_exec
EOF
echo " audit rules installed (persistent in /etc/audit/rules.d/edge-implant.rules)"
else
echo " auditd not available on this appliance - forward syslog at minimum"
fi
fi
echo ""
echo "Triage complete. Preserve memory BEFORE rebooting any suspected appliance -"
echo "these implants are memory-resident and the on-disk binaries self-delete."
One point I cannot overstate from an IR standpoint: do not reboot a suspected appliance before acquiring memory. The entire value of the execute-then-delete technique is that rebooting destroys the only copy of the implant. Capture RAM (or at minimum full /proc/<pid>/ for suspect processes) first, then isolate the device at the network layer, then image.
Remediation
Because this campaign is post-compromise tradecraft rather than a single patchable vulnerability, remediation is layered:
1. If indicators are found — treat as a full incident, not a malware cleanup.
- Isolate the appliance at the switch/firewall level; do not reboot before memory acquisition.
- Acquire volatile data (process list,
/procfor suspect PIDs, BPF state viabpftool, network connections) and memory if the platform permits. - Assume credential and configuration theft: rotate all credentials that traversed or were stored on the device, including SNMP communities, API keys, and management-plane credentials.
- Engage your IR retainer — BPF-based implants on edge gear are nation-state-grade tradecraft and typically indicate a broader intrusion set.
2. Rebuild, don't clean. For confirmed hits, reflash the appliance from known-good vendor firmware. AVERAT's six observed builds imply persistence engineering — wiping and reinstalling from trusted media is the only defensible remediation for a compromised edge device.
3. Instrument the edge tier.
- Enable syslog forwarding from every network appliance to your SIEM (Sentinel/Splunk) with process and audit events — this campaign thrives on the logging gap at the perimeter.
- Deploy auditd where the appliance OS permits, with
/sbinwrite watches and execve logging (see script above). - Add edge appliances to your Velociraptor or live-response scope wherever an agent or SSH-based acquisition is feasible.
4. Egress control for the management and appliance plane. Network devices should initiate outbound connections only to an explicit allowlist: your NTP sources, your DNS resolvers, and vendor update infrastructure. Deny-and-alert everything else. BPFDoor's passive model and low-volume egress lose most of their value when the appliance simply cannot reach arbitrary internet destinations.
5. Threat-hunt on cadence, not on incident. Schedule the KQL egress-baseline query and the VQL artifact as recurring hunts (monthly minimum for telecom/ISP infrastructure). The defining characteristic of BPFDoor historically is dwell time measured in years — periodic hunting is how you compress it.
6. Use Rapid7's released BPFDoor controller to validate detection. With the controller source now public, red teams can safely emulate the magic-packet activation pattern in a lab segment. This is a rare opportunity: you can test whether your network monitoring and your SOC actually see a real BPFDoor activation sequence, and tune accordingly.
7. Vendor pressure. For appliances where you cannot deploy any telemetry, escalate to the vendor: demand signed firmware, secure boot, and remote attestation capabilities in your procurement requirements. The reason this malware family targets the edge is precisely that we've collectively accepted edge devices as black boxes. That has to change at the contract level.
Final Word
The tradecraft here — memory-resident implants, kernel-level BPF packet filtering, self-deleting binaries, process names tuned to evade a human eyeballing ps output — reflects an adversary who has studied how network operations teams actually work and built around it. The counter is not exotic: baseline your appliances, forward their logs, restrict their egress, and hunt the two things this malware cannot hide — a process that shouldn't exist, and a /sbin that changed when nothing should have.
If your organization runs telecom, ISP, or distributed edge infrastructure and you're not confident in your visibility there, that's exactly the gap these actors are exploiting. Let's close it.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.