Hackers Plant Stealthy BPFdoor Backdoors in Telecom Networks for Long-Term Access
ID: 9b3357bd-237c-50c6-96fa-d053a23f7928
STIX ID: report--9b3357bd-237c-50c6-96fa-d053a23f7928
Feed Name: cybersecurityNews.com
Rapid7 Labs uncovered a sophisticated, state-linked campaign by Red Menshen that implants a stealthy kernel-level backdoor (BPFdoor) into telecom core infrastructure across multiple countries. The implant hides triggers inside decrypted HTTPS traffic and uses ICMP-based control channels, impersonates legitimate telecom/server processes, and targets edge infrastructure (VPNs, network devices, ESXi) to enable long-term espionage and large-scale collection of subscriber and signaling metadata. Rapid7 released detection tooling and coordinated disclosures with CERTs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
