{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/sharetech-appliances/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["Red Menshen"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SpamSniper","ShareTech appliances"],"_cs_severities":["high"],"_cs_tags":["espionage","linux","malware","telecom","network-security","red-menshen"],"_cs_type":"threat","_cs_vendors":["Jiran Group","ShareTech"],"content_html":"\u003cp\u003eThreat actors linked to the group known as Red Menshen are conducting sophisticated cyber espionage campaigns targeting telecom providers and edge network appliances in South Korea and Taiwan. The campaign involves the deployment of specialized Linux backdoors, including new variants of BPFDoor, BPF Rekoobe, and a previously unreported modular implant dubbed AVERAT. These implants are specifically designed for high-privilege environments, using regionalized disguise tactics to blend into the target environment. They achieve this by impersonating legitimate local security software, such as the SpamSniper email security solution or Oracle database background processes, and by leveraging kernel-level packet inspection to listen for trigger packets. The attackers have demonstrated agility, refining their C2 mechanisms to move from simple BPF magic packets to HTTPS POST request wrapping and SMTP-based beaconing to bypass standard deep packet inspection and network security controls common in telecom infrastructures.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial access is achieved against edge appliances, likely through exploitation of undisclosed vulnerabilities or credential abuse in regional telecom environments.\u003c/li\u003e\n\u003cli\u003eThe installer drops an ELF binary into the target directory, such as the ShareTech \u0026quot;/addpkg/sbin/\u0026quot; path.\u003c/li\u003e\n\u003cli\u003eThe dropper derives an encryption key from a hardcoded string (e.g., \u0026quot;ShareTech\u0026quot;) to decrypt a hidden shell script.\u003c/li\u003e\n\u003cli\u003eThe decrypted script executes two malicious components: a local installer (\u0026quot;ntpdate\u0026quot;) and the core payload (\u0026quot;udevds\u0026quot; / AVERAT).\u003c/li\u003e\n\u003cli\u003eThe dropper implements defense evasion by deleting itself and the intermediate script after a 10-second window to minimize footprint.\u003c/li\u003e\n\u003cli\u003eThe backdoor establishes periodic polling (600-699 seconds) to a C2 server via TCP port 25, leveraging SMTP traffic to mask C2 communications.\u003c/li\u003e\n\u003cli\u003eUpon receipt of commands, the malware performs interactive shell tasks, exfiltration, or proxying through the appliance.\u003c/li\u003e\n\u003cli\u003eThe final objective is persistent intelligence collection and data exfiltration from the compromised telecom network node.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe campaign targets sensitive telecom and network infrastructure in South Korea and Taiwan, organizations that serve as central communication hubs. Successful compromise grants attackers the ability to monitor traffic, exfiltrate subscriber data, and maintain long-term persistence on edge appliances. This activity demonstrates a focused effort to gain intelligence by compromising trusted security products (SEGs) within enterprise networks, mirroring previous campaigns against Barracuda ESG appliances.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection engineering and security operations:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAudit all Linux systems for unauthorized or suspicious raw packet sockets and BPF filters that do not align with authorized network monitoring tools.\u003c/li\u003e\n\u003cli\u003eImplement network egress filtering to restrict and monitor outbound traffic on TCP port 25 originating from non-mail service processes.\u003c/li\u003e\n\u003cli\u003eDeploy file integrity monitoring (FIM) or process execution logging to detect the creation or execution of binaries posing as system daemons (e.g., \u0026quot;udevds\u0026quot;, \u0026quot;ora_ppmond\u0026quot;).\u003c/li\u003e\n\u003cli\u003eReview the list of loaded shared object (*.so) modules to identify unauthorized extensions loaded by AVERAT (code 1010).\u003c/li\u003e\n\u003cli\u003eBlock the domain 'mx.zxopfds.com' at the enterprise DNS resolver and egress proxy as it is confirmed C2 infrastructure.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T21:05:30Z","date_published":"2026-10-06T21:05:30Z","id":"https://feed.craftedsignal.io/briefs/2026-10-linux-backdoor-espionage/","summary":"Threat actors, linked to Red Menshen, are deploying advanced Linux backdoors like BPFDoor and AVERAT against telecom and network appliances in South Korea and Taiwan, utilizing process name spoofing and BPF-based triggers to evade detection.","title":"Linux Backdoors Targeting Telecom and Network Appliances in Asia","url":"https://feed.craftedsignal.io/briefs/2026-10-linux-backdoor-espionage/"}],"language":"en","title":"CraftedSignal Threat Feed - ShareTech Appliances","version":"https://jsonfeed.org/version/1.1"}