ConciseSignal
Following

Stealthy Linux backdoors pose as email tools in Asia

Researchers have identified new Linux backdoors targeting telecom and network-edge devices in South Korea and Taiwan. The malware, detailed by Rapid7, mimics legitimate email and security services to evade detection, sending command-and-control traffic disguised as standard mail activity. Some variants adopt process names from well-known anti-spam products, hindering identification. At least one implant communicates through port 25 and uses typical email protocols to blend in with business network traffic.

Why it mattersTelecom and critical network infrastructure in Asia are being compromised by advanced, stealthy malware. The use of familiar services and protocols makes detection difficult, raising concerns for defenders and organizations relying on similar appliances.

Sources covering this

Infosecurity MagazineNew Stealthy Linux Backdoors Target Telecoms, Masquerade as Email Traffic2:00 PM →The Hacker NewsLinux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan6:24 PM →
Concise Signal DailyEnterprise AI, security & business tech.Weekdays, 7am Eastern · Sample issue

More in Cybersecurity