logo

Hackers Plant Stealthy BPFdoor Backdoors in Telecom Networks for Long-Term Access

ID: 9b3357bd-237c-50c6-96fa-d053a23f7928

STIX ID: report--9b3357bd-237c-50c6-96fa-d053a23f7928

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-03-26

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Rapid7 Labs uncovered a sophisticated, state-linked campaign by Red Menshen that implants a stealthy kernel-level backdoor (BPFdoor) into telecom core infrastructure across multiple countries. The implant hides triggers inside decrypted HTTPS traffic and uses ICMP-based control channels, impersonates legitimate telecom/server processes, and targets edge infrastructure (VPNs, network devices, ESXi) to enable long-term espionage and large-scale collection of subscriber and signaling metadata. Rapid7 released detection tooling and coordinated disclosures with CERTs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.