{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Passive BPF backdoors do not maintain open listening ports and are invisible to conventional vulnerability scans; identifying the hidden trigger mechanisms is the only way to detect them."
      },
      "name": "BPFDoor and AVERAT Passive Network Tunneling",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1572",
        "attack.t1071.001",
        "attack.t1071.003",
        "attack.t1041",
        "command and control",
        "defense evasion",
        "execution",
        "persistence",
        "osctrl"
      ],
      "series": {
        "slug": "smtp-is-the-key-bpfdoor-and-averat-hitting-the-network-edge",
        "index": 2,
        "title": "SMTP is the key: BPFDoor and AVERAT hitting the network edge",
        "total": 2
      },
      "related": [
        {
          "hunt": "linux-process-spoofing-watchdog",
          "reason": "This hunt focuses on the network trigger; a sibling hunt handles the behavioral process spoofing of ntpdate and udevds.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "resident-watchdog-masquerading-linux-edge",
          "relation": "follows"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "osctrl": {
          "name": "osctrl",
          "category": "siem",
          "huntbase": {
            "product": "osctrl"
          }
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A simple rule might find port 25 traffic, but this hunt correlates regionalized disguise (SMTP symmetry) with eBPF-level raw socket attachments and specific HTTP protocol tunneling offsets, providing context a single rule cannot reach.",
      "coverage": [
        {
          "stage": "passive-bpf-backdoor",
          "steps": [
            "bpf-raw-sockets"
          ],
          "status": "covered"
        },
        {
          "stage": "network-traffic-blending",
          "steps": [
            "smtp-symmetry-prevalence",
            "http-trigger-detection"
          ],
          "status": "covered"
        },
        {
          "stage": "averat-dropper-installation",
          "reason": "Belongs to another part of the 'SMTP is the key: BPFDoor and AVERAT hitting the network edge' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "staging-shell-script",
          "reason": "Belongs to another part of the 'SMTP is the key: BPFDoor and AVERAT hitting the network edge' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "process-masquerading",
          "reason": "Belongs to another part of the 'SMTP is the key: BPFDoor and AVERAT hitting the network edge' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "forensic-evasion",
          "reason": "Belongs to another part of the 'SMTP is the key: BPFDoor and AVERAT hitting the network edge' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "AVERAT Dropper Installation",
            "slug": "averat-dropper-installation",
            "tactic": "execution",
            "techniques": [
              "T1059"
            ],
            "observables": [
              "dropper binary located in add-on package directory /addpkg/sbin/update",
              "SHA256: 2bedc26d4b29b435c21962beed7db21188a0219a0d28334bba8b4fb1656d7b15",
              "AES-128-ECB key derived from string 'ShareTech'"
            ]
          },
          {
            "name": "Staging via Shell Script",
            "slug": "staging-shell-script",
            "tactic": "persistence",
            "techniques": [
              "T1059.004"
            ],
            "observables": [
              "shell script written to storage mount /HDD/ms6x2xTo64/updIptable.php",
              "watchdog marker file /HDD/ms6x2xTo64/execProcEnd",
              "secondary payloads staged in /sbin/ntpdate and /sbin/udevds"
            ]
          },
          {
            "name": "Process Identity Masquerading",
            "slug": "process-masquerading",
            "tactic": "defense-evasion",
            "techniques": [
              "T1036.004"
            ],
            "observables": [
              "process names: ntpdate, udevds, abrtd, chronyd, rsyslogd, crond, python, ora_ppmond, dtnpd, ofgmd, earsd, httpd, snipe-smtpd",
              "PID file: /var/run/spamsniper.pid",
              "processes running with on_disk = false after self-deletion"
            ]
          },
          {
            "name": "Passive BPF Backdoor",
            "slug": "passive-bpf-backdoor",
            "tactic": "command-and-control",
            "techniques": [
              "T1572"
            ],
            "observables": [
              "attachment of BPF filters to PF_PACKET raw sockets",
              "magic bytes: 0x6693 (UDP), 0x4274 (TCP), 0x7820 (ICMP), 0x5571",
              "handshake sequence: 50 01 13 3F 08 5C 73 7B 1A 72 53 78"
            ]
          },
          {
            "name": "C2 Traffic Blending",
            "slug": "network-traffic-blending",
            "tactic": "command-and-control",
            "techniques": [
              "T1071.001",
              "T1071.003"
            ],
            "observables": [
              "SMTP traffic with source and destination ports equal to 25",
              "HTTPS POST requests with mathematical padding to /admin/login.aspx?id=99990",
              "URL paths: /admin/login.aspx, updiptable.php",
              "integrated Tiny Shell command opcodes: S, U, D"
            ]
          },
          {
            "name": "Command History Evasion",
            "slug": "forensic-evasion",
            "tactic": "defense-evasion",
            "techniques": [
              "T1562"
            ],
            "observables": [
              "execution of environment variable overrides: HISTFILE=/dev/null, HISTSIZE=0, VIMINIT='set viminfo='"
            ]
          }
        ],
        "summary": "A campaign targeting Linux-based telecom edge appliances in South Korea and Taiwan using a multi-stage infection chain involving the AVERAT dropper and BPFDoor/Rekoobe implants. The campaign utilizes regionalized process masquerading, passive BPF-based triggers, and traffic blending over SMTP and HTTPS to maintain persistent, stealthy access to network infrastructure."
      },
      "severity": "high",
      "rationale": "Focus on Linux-based edge appliances, firewalls, and mail relay systems. Prioritize systems running South Korean (SpamSniper) or Taiwanese (ShareTech) vendor platforms.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary has deployed a passive BPF-based backdoor that remains dormant until triggered by specially crafted SMTP or HTTPS traffic, allowing for protocol tunneling without maintaining an open listening port.",
      "parameters": {
        "scope_hosts": {
          "from": {
            "ref": "analyst-defined",
            "kind": "manual",
            "observed": "2024-05-20"
          },
          "type": "list[host]",
          "default": [],
          "description": "Optional list of hostnames to focus the hunt on."
        },
        "lookback_days": {
          "from": {
            "ref": "retention-standard",
            "kind": "manual",
            "observed": "2024-05-20"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "trigger_paths": {
          "from": {
            "ref": "rapid7-bpfdoor-2026",
            "kind": "article",
            "observed": "2026-10-02"
          },
          "type": "list[path]",
          "default": [
            "/admin/login.aspx",
            "/updiptable.php"
          ],
          "description": "Known URL paths used for HTTPS tunneling triggers."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.rapid7.com/blog/post/tr-smtp-is-the-key-bpfdoor-averat-hitting-the-network-edge",
          "gates": [
            "dry-run",
            "lint",
            "critic"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.rapid7.com/blog/post/tr-smtp-is-the-key-bpfdoor-averat-hitting-the-network-edge",
          "name": "Rapid7 \u2014 SMTP is the key: BPFDoor and AVERAT hitting the network edge"
        }
      ],
      "blind_spots": [
        {
          "id": "bpf-hostname-missing",
          "risk": "Identifying the target host requires manual correlation between process IDs and timestamps across different sources.",
          "owner": "Telemetry Team",
          "stage": "passive-bpf-backdoor",
          "question": "which specific host recorded a raw socket attachment",
          "requires": "a hostname column in the bpf_socket_events table",
          "remediation": "Update the osctrl bpf_socket_events mapping to include the reporting device hostname."
        },
        {
          "id": "ssl-encryption-blindness",
          "risk": "If the edge proxy does not offload SSL and log query strings, the trigger signal remains invisible to this hunt.",
          "owner": "Network Engineering",
          "stage": "network-traffic-blending",
          "question": "whether the HTTPS triggers contain the specific 9999 padding",
          "requires": "decrypted HTTP query parameters from the edge proxy",
          "remediation": "Enable SSL termination and full URL query logging at the edge proxy layer."
        }
      ]
    },
    "name": "BPFDoor and AVERAT Passive Network Tunneling",
    "description": "This hunt targets the network-level persistence and command-and-control mechanisms used by BPFDoor and AVERAT. These implants do not open traditional ports; instead, they use Berkeley Packet Filters (BPF) to sniff for magic sequences in existing traffic streams like SMTP and HTTPS. The hunt looks for symmetric SMTP traffic (port 25 to port 25) characteristic of BPF Rekoobe, unusual raw AF_PACKET socket attachments, and mathematically padded HTTPS requests designed to land triggers at specific TCP offsets. An agent weighs these independent signals to identify systems acting as stealthy network-edge backdoors."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "smtp-is-the-key-bpfdoor-and-averat-hitting-the-network-edge",
          "index": 2,
          "title": "SMTP is the key: BPFDoor and AVERAT hitting the network edge",
          "total": 2
        },
        "coverage": [
          {
            "stage": "passive-bpf-backdoor",
            "steps": [
              "bpf-raw-sockets"
            ],
            "status": "covered"
          },
          {
            "stage": "network-traffic-blending",
            "steps": [
              "smtp-symmetry-prevalence",
              "http-trigger-detection"
            ],
            "status": "covered"
          },
          {
            "stage": "averat-dropper-installation",
            "reason": "Belongs to another part of the 'SMTP is the key: BPFDoor and AVERAT hitting the network edge' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "staging-shell-script",
            "reason": "Belongs to another part of the 'SMTP is the key: BPFDoor and AVERAT hitting the network edge' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "process-masquerading",
            "reason": "Belongs to another part of the 'SMTP is the key: BPFDoor and AVERAT hitting the network edge' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "forensic-evasion",
            "reason": "Belongs to another part of the 'SMTP is the key: BPFDoor and AVERAT hitting the network edge' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary has deployed a passive BPF-based backdoor that remains dormant until triggered by specially crafted SMTP or HTTPS traffic, allowing for protocol tunneling without maintaining an open listening port.",
        "blind_spots": [
          {
            "id": "bpf-hostname-missing",
            "risk": "Identifying the target host requires manual correlation between process IDs and timestamps across different sources.",
            "owner": "Telemetry Team",
            "stage": "passive-bpf-backdoor",
            "question": "which specific host recorded a raw socket attachment",
            "requires": "a hostname column in the bpf_socket_events table",
            "remediation": "Update the osctrl bpf_socket_events mapping to include the reporting device hostname."
          },
          {
            "id": "ssl-encryption-blindness",
            "risk": "If the edge proxy does not offload SSL and log query strings, the trigger signal remains invisible to this hunt.",
            "owner": "Network Engineering",
            "stage": "network-traffic-blending",
            "question": "whether the HTTPS triggers contain the specific 9999 padding",
            "requires": "decrypted HTTP query parameters from the edge proxy",
            "remediation": "Enable SSL termination and full URL query logging at the edge proxy layer."
          }
        ],
        "scoping_notes": "Focus on Linux-based edge appliances, firewalls, and mail relay systems. Prioritize systems running South Korean (SpamSniper) or Taiwanese (ShareTech) vendor platforms.",
        "beyond_detection": "A simple rule might find port 25 traffic, but this hunt correlates regionalized disguise (SMTP symmetry) with eBPF-level raw socket attachments and specific HTTP protocol tunneling offsets, providing context a single rule cannot reach."
      }
    },
    {
      "id": "smtp-symmetry-prevalence",
      "type": "query",
      "label": "Symmetric SMTP traffic prevalence",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "network",
        "content": "SELECT src_endpoint_ip, dst_endpoint_ip, COUNT(DISTINCT device_hostname) AS host_count, COUNT(*) AS event_count FROM hb_network_connection WHERE (src_endpoint_port = 25 AND dst_endpoint_port = 25) AND state_kind = 'log' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY src_endpoint_ip, dst_endpoint_ip HAVING host_count <= 5 ORDER BY host_count ASC",
        "surface": "hb_network_connection",
        "description": "Identify rare network connections where both the source and destination ports are 25, which indicates BPF Rekoobe blending with MTA relay traffic.",
        "expected_signal": "A small number of hosts showing symmetric port 25 traffic. While normal for mail servers, it is rare for general workstations or specific edge appliances not acting as relays."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Symmetric SMTP traffic prevalence",
        "reads": [
          "src_endpoint_ip",
          "dst_endpoint_ip",
          "device_hostname",
          "time"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT src_endpoint_ip, dst_endpoint_ip, COUNT(DISTINCT device_hostname) AS host_count, COUNT(*) AS event_count FROM hb_network_connection WHERE (src_endpoint_port = 25 AND dst_endpoint_port = 25) AND state_kind = 'log' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY src_endpoint_ip, dst_endpoint_ip HAVING host_count <= 5 ORDER BY host_count ASC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A small number of hosts showing symmetric port 25 traffic. While normal for mail servers, it is rare for general workstations or specific edge appliances not acting as relays.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "src_endpoint_ip",
            "dst_endpoint_ip"
          ],
          "rare_below": 5
        },
        "verified_at": "2026-10-03"
      }
    },
    {
      "id": "bpf-raw-sockets",
      "type": "query",
      "label": "Raw PF_PACKET socket creation",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "osctrl",
        "content": "SELECT path, pid, local_address, remote_address, time FROM bpf_socket_events WHERE family = 17 AND time >= (strftime('%s', 'now') - ({{lookback_days}} * 86400))",
        "product": "osctrl",
        "surface": "bpf_socket_events",
        "extension": "osctrl",
        "description": "Detect the creation of AF_PACKET sockets used by BPF-based backdoors to sniff network traffic without binding to a port.",
        "expected_signal": "Processes opening AF_PACKET (family 17) sockets. This is rare for standard applications and indicates the presence of a sniffer or BPF implant."
      },
      "parents": [
        {
          "id": "smtp-symmetry-prevalence"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Raw PF_PACKET socket creation",
        "reads": [
          "path",
          "pid",
          "family",
          "local_address",
          "remote_address",
          "time"
        ],
        "source": "bpf_socket_events",
        "target": "osctrl",
        "content": "SELECT path, pid, local_address, remote_address, time FROM bpf_socket_events WHERE family = 17 AND time >= (strftime('%s', 'now') - ({{lookback_days}} * 86400))",
        "silence": "not_evidence_of_absence",
        "expected": "Processes opening AF_PACKET (family 17) sockets. This is rare for standard applications and indicates the presence of a sniffer or BPF implant.",
        "verified": "dry-run",
        "verified_at": "2026-10-03",
        "target_extension": "osctrl"
      }
    },
    {
      "id": "http-trigger-detection",
      "type": "query",
      "label": "HTTPS triggers with mathematical padding",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "web",
        "content": "SELECT device_hostname, url_path, url_query, user_agent, src_endpoint_ip, time FROM hb_http_activity WHERE (instr(',' || '{{trigger_paths}}' || ',', ',' || LOWER(url_path) || ',') > 0 OR url_query LIKE '%9999%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_http_activity",
        "description": "Search for HTTP POST requests to trigger paths that include specific query padding designed to place payloads at predictable TCP offsets.",
        "expected_signal": "POST requests to admin or script paths containing '9999' in the query string. This aligns with the trigger mechanism of the Rapid7 BPFDoor controller."
      },
      "parents": [
        {
          "id": "smtp-symmetry-prevalence"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "HTTPS triggers with mathematical padding",
        "reads": [
          "device_hostname",
          "url_path",
          "url_query",
          "user_agent",
          "src_endpoint_ip",
          "time"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, url_path, url_query, user_agent, src_endpoint_ip, time FROM hb_http_activity WHERE (instr(',' || '{{trigger_paths}}' || ',', ',' || LOWER(url_path) || ',') > 0 OR url_query LIKE '%9999%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "POST requests to admin or script paths containing '9999' in the query string. This aligns with the trigger mechanism of the Rapid7 BPFDoor controller.",
        "verified": "dry-run",
        "verified_at": "2026-10-03"
      }
    },
    {
      "id": "triage-signals",
      "type": "analytic",
      "label": "Triage passive implant signals",
      "config": {
        "cite": "required",
        "tools": [
          "network",
          "osctrl",
          "web"
        ],
        "context": [
          "smtp-symmetry-prevalence",
          "bpf-raw-sockets",
          "http-trigger-detection"
        ],
        "objective": "Analyze the results from the SMTP, BPF socket, and HTTP trigger queries. Determine if a system is likely infected with a passive backdoor based on concurrent activity across these three surfaces.",
        "description": "Evaluate whether the combined network and socket telemetry indicates a passive backdoor.",
        "max_iterations": 4,
        "expected_signal": "A host-by-host verdict linking triggers to process socket activity.",
        "success_criteria": "A verdict of malicious, suspicious, or benign for each host, citing specific PIDs and source IPs."
      },
      "parents": [
        {
          "id": "bpf-raw-sockets",
          "kind": "merge"
        },
        {
          "id": "http-trigger-detection",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-verdict",
      "type": "checkpoint",
      "label": "Route based on agent verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage verdict identifies malicious passive backdoor activity on at least one host",
        "condition": "the triage verdict identifies malicious passive backdoor activity on at least one host",
        "blind_spot": "bpf-hostname-missing",
        "confidence": "high",
        "description": "Direct the hunt to containment or manual review based on the triage result.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-signals"
        }
      ]
    },
    {
      "id": "isolate-endpoint",
      "type": "action",
      "label": "Isolate endpoint",
      "config": {
        "target": "endpoint",
        "description": "Contain the suspected system to prevent command execution via the passive tunnel.",
        "instructions": "Isolate the endpoint. Do not reboot or terminate processes, as the BPF filters may only reside in memory. Capture a memory dump for forensic analysis.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "forensic-verification",
      "type": "task",
      "label": "Forensic verification",
      "config": {
        "assignee": "analyst",
        "description": "Verify the agent findings and investigate the resident process.",
        "instructions": "Manually correlate the PIDs found in bpf_socket_events with the hb_process_activity surface to identify the process name and command line. Check if the process image is deleted (on_disk = 0). Review web logs for the source IP of the padded HTTP triggers."
      },
      "parents": [
        {
          "id": "route-verdict",
          "branch": "default"
        },
        {
          "id": "route-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-endpoint"
        }
      ]
    },
    {
      "id": "hunt-closure",
      "type": "task",
      "label": "Hunt closure",
      "config": {
        "assignee": "analyst",
        "description": "Document findings and update detections.",
        "instructions": "Summarize the findings. If symmetric SMTP was confirmed, suggest a detection rule for persistent tcp/25-to-25 connections on non-mail-relay systems."
      },
      "parents": [
        {
          "id": "route-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "forensic-verification"
        }
      ]
    }
  ]
}