New BPFDoor Variants Use Stateless C2 and ICMP Relays to Evade Detection
ID: 11c4e21b-3598-535d-92e8-61f4a6304edf
STIX ID: report--11c4e21b-3598-535d-92e8-61f4a6304edf
Feed Name: cybersecurityNews.com
Threat Score
**BPFDoor has resurfaced with advanced icmpShell and httpShell variants that abuse Linux BPF to remain invisible, implement stateless command-and-control (using a broadcast -1 flag), and perform ICMP relaying to tunnel commands inside telecom infrastructure; Rapid7 links the activity to the China-nexus APT Red Menshen and recommends monitoring raw socket usage, auditing process names, and watching for anomalous ICMP traffic.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
