logo

New BPFDoor Variants Use Stateless C2 and ICMP Relays to Evade Detection

ID: 11c4e21b-3598-535d-92e8-61f4a6304edf

STIX ID: report--11c4e21b-3598-535d-92e8-61f4a6304edf

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-04-07

Date Updated: 2026-05-05

Author: Tushar Subhra Dutta

...
...

**BPFDoor has resurfaced with advanced icmpShell and httpShell variants that abuse Linux BPF to remain invisible, implement stateless command-and-control (using a broadcast -1 flag), and perform ICMP relaying to tunnel commands inside telecom infrastructure; Rapid7 links the activity to the China-nexus APT Red Menshen and recommends monitoring raw socket usage, auditing process names, and watching for anomalous ICMP traffic.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.