Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan Ravie LakshmananOct 06, 2026Cyber Espionage / Malware Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection. Threat actors are known to name their malicious software after a legitimate operating system component or a process as a defense evasion measure. By borrowing the name of a real binary, it may make it appear less conspicuous among other Windows processes, lend it a false sense of trust, or be overlooked by an analyst during casual inspection. However, the backdoors examined by Rapid7 have been found to go beyond…
CVEs: CVE-2023-2868, CVE-2023-7102, CVE-2026-88772
Original source: thehackernews.com