{"id":244985,"date":"2026-10-06T22:05:33","date_gmt":"2026-10-07T03:05:33","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/10\/linux-backdoors-impersonate-email-security-tools-to-evade-detection-in-korea-and-taiwan"},"modified":"2026-10-06T22:05:33","modified_gmt":"2026-10-07T03:05:33","slug":"linux-backdoors-impersonate-email-security-tools-to-evade-detection-in-korea-and-taiwan","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/10\/linux-backdoors-impersonate-email-security-tools-to-evade-detection-in-korea-and-taiwan","title":{"rendered":"Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/linux-backdoors-impersonate-email-security-tools-to-evade-detection-in-korea-and-taiwan.webp\"><\/a><\/p>\n<p>Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection.<\/p>\n<p>Threat actors are known to name their malicious software after a legitimate operating system component or a process as a defense evasion measure. By borrowing the name of a real binary, it may make it appear less conspicuous among other Windows processes, lend it a false sense of trust, or be overlooked by an analyst during casual inspection.<\/p>\n<p>However, the backdoors <a href=\"https:\/\/www.rapid7.com\/blog\/post\/tr-smtp-is-the-key-bpfdoor-averat-hitting-the-network-edge\/\" target=\"_blank\">examined<\/a> by Rapid7 have been found to go beyond imitating file names by assuming the identities of email security products like <a href=\"https:\/\/global.jiran.com\/spamsniper\" target=\"_blank\">SpamSniper<\/a> and <a href=\"https:\/\/www.sharetech.com.tw\/en-us\/\" target=\"_blank\">ShareTech<\/a> that are widely used in enterprise environments in South Korea and Taiwan.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection. Threat actors are known to name their malicious software after a legitimate operating system component or a process as a defense evasion measure. By borrowing [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1523,1492],"tags":[],"class_list":["post-244985","post","type-post","status-publish","format-standard","hentry","category-computing","category-security"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/244985","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=244985"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/244985\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=244985"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=244985"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=244985"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}