Linux Backdoors Disguised as Email Security Tools Target Telecom Infrastructure in Korea and Taiwan
Threat actors impersonate legitimate processes to evade detection and maintain persistent access to network appliances

Key Takeaways
- Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising traffic as email services and legitimate processes.
- The malware employs defense evasion techniques by borrowing legitimate binary names and mimicking email service traffic to avoid detection.
Related Security News

ClickFix Attacks Evolve to Better Hide Malicious Payloads
Threat actors have updated their ClickFix social engineering campaign to conceal malicious payloads using DNS TXT records and browser cache pre-fetching techniques. These changes make early detection more difficult, though the core social engineering lure remains unchanged. Security teams are advised to monitor for anomalous DNS activity and browser behavior as part of a layered defense.




