#BPFdoor
Security researcher HaxRob has published a two-part technical analysis of BPFDoor, a malware strain that targets Linux and has been linked to some past APT activity.

The report also covers recent versions of the malware spotted this year.

haxrob.net/bpfdoor-past...

haxrob.net/bpfdoor-past...
BPFDoor - Part 1 - The past
An exploration the archeological roots of the BPFDoor Linux malware.
haxrob.net
June 3, 2025 at 10:48 AM
-Russia to use custom crypto in 5G network
-Orban government accused of using Candiru spyware
-Coruna tied to Triangulation
-Malware found on thousands of Luxembourg government phones
-More advanced BPFdoor versions spotted

Podcast: risky.biz/RBNEWS543/
Newsletter: news.risky.biz/risky-bullet...
March 27, 2026 at 10:14 AM
Researchers release tool to detect stealthy BPFDoor implants in critical infrastructure networks

📖 Read more: www.helpnetsecurity.com/2026/03/26/t...

#cybersecurity #cybersecuritynews #backdoor #malware #Linux @rapid7.com
Researchers release tool to detect stealthy BPFDoor implants in critical infrastructure networks - Help Net Security
Researchers have released a scanning script to help with detection of hard-to-spot BPFDoor implants used by Salt Typhoon.
www.helpnetsecurity.com
March 26, 2026 at 1:30 PM
The S2W Threat Research and Intelligence Center (TALON) recently confirmed and analysed the BPFDoor malware that was being distributed to Korean companies. medium.com/s2wblog/deta...
May 6, 2025 at 11:08 AM
Rapid7 links BPFDoor deployments on telco networks to Chinese APT Red Menshen

www.rapid7.com/blog/post/tr...
BPFdoor in Telecom Networks: Sleeper Cells in the backbone
A months-long investigation by Rapid7 Labs has uncovered evidence of an advanced China-nexus threat actor placing stealthy digital sleeper cells in telecommunications networks, in order to carry out h...
www.rapid7.com
March 26, 2026 at 7:57 PM
More BPFDoor analysis from S2W: medium.com/s2wblog/deta...
Looks like the BPFDoor malware was involved in the SK Telecom hack

x.com/mstoned7/sta...

Meanwhile, the telco started replacing all customer SIM cards... will probably take a year to complete since it doesn't even have a 1/25 of the needed cards
May 1, 2025 at 1:26 PM
New BPFDoor Controller Enables Stealthy Lateral Movement in Linux Server Attacks
New BPFDoor Controller Enables Stealthy Lateral Movement in Linux Server Attacks
thehackernews.com
April 16, 2025 at 11:01 AM
-eXch mixer shuts down
-EquationDrug bootkit spotted in the wild
-State-backed hacktivism is mostly NoName057 DDoS attacks
-SMA exploitation hits old devices
-Raytheon fined for cybersecurity woes
-New Golden Chickens malware
-Reports on Pupkin Stealer, NullPoint Stealer, EyePyramidC2, BPFDoor
May 2, 2025 at 6:34 AM
Symbiote and BPFDoor for eBPF powered malware in the wild, that are documented. Thanks @alexplaskett.bsky.social. Theres blogposts, from Elastic and Blackbeery respectively, great reads!
December 9, 2024 at 12:44 PM
Stealthy and persistent: #BPFdoor is back, slipping past defenses with almost no trace. Learn how this elusive Linux backdoor hides in plain sight and what it means for enterprise security. Full analysis by @TrendMicro: https://www.trendmicro.com/en_us/research/25/d/bpfdoor-hidden-controller.html
BPFDoors Hidden Controller Used Against Asia, Middle East Targets
A controller linked to BPF backdoor can open a reverse shell, enabling deeper infiltration into compromised networks. Recent attacks have been observed targeting the telecommunications, finance, and retail sectors across South Korea, Hong Kong, Myanmar, Malaysia, and Egypt.
www.trendmicro.com
April 14, 2025 at 10:44 AM
China Upgrades the Backdoor It Uses to Spy on Telcos Globally
China Upgrades the Backdoor It Uses to Spy on Telcos Globally
Chinese APT Red Menshen's super-advanced BPFdoor malware defeats traditional cybersecurity protections. All telcos can do, really, is try hunting it down.
www.darkreading.com
March 27, 2026 at 5:20 PM
Interesting Git repos of the week:

Threats:

* https://github.com/haxrob/BPFDoor-controller-source - yay, BPFDoor source

Detection:

* https://github.com/davidjurgens/hallucinated-reference-finder - how many of those references are horseshit?
* https://github.com/Cybereason-Public/owLSM - […]
Original post on infosec.exchange
infosec.exchange
April 3, 2026 at 5:51 PM
아이씨 KT도 bpfdoor 맞았어???
KT 해킹 숨기고 결제정보까지 털렸다…정부 ‘역대급 제재’ 임박
2025. 11. 06 16:02 작성

'BPF도어' 서버 43대 감염 숨기고 '조용히 조치'

소액결제 피해 확산에 법적 책임 '정조준'

lawtalknews.co.kr/article/751W...
lawtalknews.co.kr
November 6, 2025 at 12:24 PM
BPFDoor and Symbiote Rootkits Attacking Linux Systems Exploiting eBPF Filters
BPFDoor and Symbiote Rootkits Attacking Linux Systems Exploiting eBPF Filters
cybersecuritynews.com
December 3, 2025 at 9:20 AM
Hackers Plant Stealthy BPFdoor Backdoors in Telecom Networks for Long-Term Access
Hackers Plant Stealthy BPFdoor Backdoors in Telecom Networks for Long-Term Access
A months-long investigation by Rapid7 Labs has exposed a sophisticated, state-sponsored espionage campaign by the China-nexus threat actor Red Menshen, which has embedded some of the most covert digital sleeper cells ever documented inside global telecommunications infrastructure. Released on March 26, 2026, the findings reveal a deliberate shift from opportunistic hacking to long-term pre-positioning within the very backbone networks that underpin national and international communications. Telecommunications networks carry government communications, authenticate subscriber identities, coordinate critical industries, and process signaling flows across national borders. At their core, these environments rely on specialized protocols such as SS7 , Diameter, and SCTP to manage subscriber identity, mobility, and global connectivity, making them uniquely valuable for intelligence collection far beyond what a conventional data breach enables. Persistent access within a telecom core can expose subscriber identifiers, mobility events, authentication exchanges, and communication metadata, enabling large-scale tracking of high-value geopolitical targets. Red Menshen has specifically targeted telecom providers across South Korea, Hong Kong, Myanmar, Malaysia, Egypt, and the Middle East, with collateral risk extending to government networks that depend on those carriers. BPFdoor: A Kernel-Level Trapdoor At the center of this campaign is BPFdoor, a stealth Linux backdoor engineered to operate within the operating system kernel by abusing Berkeley Packet Filter (BPF) functionality. Unlike conventional malware, BPFdoor does not open listening ports or generate visible command-and-control beaconing. Instead, it installs a custom BPF filter inside the kernel that silently inspects incoming traffic, activating only when it receives a specially crafted “magic packet” containing a predefined byte sequence. Tools such as netstat, ss, or nmap show nothing unusual; the system appears entirely clean. Rapid7 Labs identified a previously undocumented BPFdoor variant that significantly advances its stealth capabilities. Rather than relying on a detectable magic packet, the updated variant now conceals command triggers within legitimate HTTPS traffic, exploiting SSL termination points like load balancers and reverse proxies to deliver activation commands after decryption in the internal network zone. A sophisticated “magic ruler” padding mechanism ensures a marker string (“9999”) always lands at a fixed 26-byte or 40-byte offset within inspected request data, allowing the implant to survive proxy header rewriting, effectively creating dynamic Layer-7 camouflage. The variant also employs an ICMP-based control channel, where compromised servers relay commands to each other using crafted ICMP packets embedded with the value 0xFFFFFFFF as a “do not forward” terminal signal, enabling lateral propagation without standard C2 traffic. Infrastructure-Level Masquerading Some BPFdoor samples mimic legitimate processes on HPE ProLiant bare-metal servers, specifically impersonating hpasmlited, a daemon belonging to HPE’s Agentless Management Service, to blend into telecom hardware environments running 4G/5G core workloads. Other samples spoof Docker and containerd components, targeting Kubernetes-hosted 5G core functions such as AMF, SMF, and UDM. Initial access consistently targets edge infrastructure: Ivanti Connect Secure VPNs, Cisco and Juniper network devices, Fortinet firewalls, and VMware ESXi hosts. Post-exploitation tooling includes CrossC2, TinyShell, SSH brute-forcers, and custom ELF keyloggers with telecom-aware credential lists referencing terms like “imsi.” Rapid7 has coordinated with national CERTs and government partners to notify affected organizations. The firm released a free, open-source scanning script capable of detecting both legacy and new BPFdoor variants to assist organizations in rapid exposure validation. Defenders are strongly advised to expand visibility into kernel-level operations, raw BPF filter activity, and anomalous high-port behavior on Linux systems — areas where most organizations currently lack adequate monitoring depth. Follow us on Google News , LinkedIn , and X for daily cybersecurity updates. Contact us to feature your stories. The post Hackers Plant Stealthy BPFdoor Backdoors in Telecom Networks for Long-Term Access appeared first on Cyber Security News .
cybersecuritynews.com
March 26, 2026 at 4:30 PM
📢 BPFDoor : Rapid7 identifie 7 nouveaux variants furtifs avec balises actives et ciblage HPE ProLiant
📝 ## 🔍 Contexte

Publié le 2 avril 2…
https://cyberveille.ch/posts/2026-04-03-bpfdoor-rapid7-identifie-7-nouveaux-variants-furtifs-avec-balises-actives-et-ciblage-hpe-proliant/ #BPFDoor #Cyberveille
April 3, 2026 at 8:30 PM
이번 통신사(skt) 악성코드 해시 떴네요. BPFDoor가 맞았습니다.
April 25, 2025 at 5:05 PM
BPFDoor resurfaces in Asian/Middle East cyberespionage campaigns, leveraging BPF filters for stealth. Defenders should monitor for unusual network sockets and review eBPF-enabled systems.

Technical details: securityonline.info/bpfdoor-back... #ThreatIntel
BPFDoor Backdoor Used in Asia, Middle East Cyberespionage
Trend Micro uncovers BPFDoor backdoor used in cyberespionage across Asia and the Middle East, attributing it to the Red Menshen APT group
securityonline.info
April 16, 2025 at 7:16 AM
China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy via Telecom Networks reconbee.com/china-linked...

#china #chinese #RedMenshen #BPFDoor #spy #telecomnetwork #potatoattack
March 27, 2026 at 7:53 AM