Stealthy Linux backdoors pose as email tools in Asia
Researchers have identified new Linux backdoors targeting telecom and network-edge devices in South Korea and Taiwan. The malware, detailed by Rapid7, mimics legitimate email and security services to evade detection, sending command-and-control traffic disguised as standard mail activity. Some variants adopt process names from well-known anti-spam products, hindering identification. At least one implant communicates through port 25 and uses typical email protocols to blend in with business network traffic.
- Backdoors target devices in South Korea and Taiwan
- Malware camouflages itself as common network processes
- Some variants mimic well-known anti-spam program names
- Command traffic uses port 25 to appear as normal email
- Attribution is ongoing; full scope is yet unclear
Sources covering this
More in Cybersecurity
Hackers send extortion message through ASOS app
Hackers took control of ASOS's app notification system and sent a message to users claiming to have breached the company's Snowflake…
ClickFix attacks use browser cache to smuggle payloads
A recent ClickFix campaign is hiding malicious Visual Basic scripts disguised as image files in browser caches on victims' devices,…
Phishing campaign uses fake AI ad tools to steal credentials
Researchers report a phishing operation targeting digital advertising professionals through counterfeit AI tools like ChatGPT, Gemini,…
Nikkei reveals breaches of employee email accounts
Japanese media group Nikkei disclosed that two employee cloud email accounts were breached in separate incidents this year.