Back to all lessons
Awareness Lessons
4 days ago

Linux Backdoors Masquerade as Legitimate Tools to Evade Detection

The Red Menshen threat group deployed Linux backdoors (including BPFDoor variants and AVERAT) on telecom and network appliances in South Korea and Taiwan by disguising malicious traffic and processes as trusted email security products and Oracle database services. This technique — known as process masquerading — exploits the assumption that familiar process names are inherently safe, allowing attackers to persist undetected for extended periods. The attack highlights a critical gap in runtime process validation and network traffic inspection, particularly on appliances that are often less rigorously monitored than traditional endpoints. Organizations that rely solely on name-based allowlisting or signature detection without behavioral analysis are especially vulnerable to this class of evasion.

Tactical Insight

Immediate actions

  • Audit all running processes on Linux-based network appliances and telecom systems, verifying each process binary's hash and path against known-good baselines.
  • Deploy network traffic inspection tools capable of deep packet inspection to detect anomalous traffic patterns regardless of the port or service name used.
  • Isolate confirmed or suspected compromised appliances from the broader network immediately pending forensic investigation.

Detection measures

  • Implement behavioral-based EDR or host-based intrusion detection (e.g., auditd, Falco) on Linux systems to flag processes that use BPF filters or make unexpected outbound connections.
  • Establish baseline network flow profiles for all telecom and network appliances and alert on deviations, especially unexpected email-protocol traffic from non-mail servers.
  • Correlate process name, binary path, parent process, and network activity together — not process name alone — to detect masquerading techniques.

Long-term improvements

  • Enforce strict network segmentation around telecom and network appliances, limiting lateral movement and unauthorized outbound communication channels.
  • Maintain a continuously updated and verified inventory of all software running on network appliances, including version, hash, and expected behavior.
  • Conduct regular threat-hunting exercises focused on living-off-the-land and process masquerading techniques targeting Linux infrastructure.