logo

A peek behind the BPFDoor

ID: 11aa3fca-9d86-59df-bbe3-932ef3fe3e72

STIX ID: report--11aa3fca-9d86-59df-bbe3-932ef3fe3e72

Feed Name: Elastic Security Labs

Threat Score
85/100

Date Published: 2022-07-13

Date Updated: 2026-04-27

...
...

BPFDoor is a sophisticated, long-lived Linux backdoor that leverages raw sockets and kernel-level BPF filters to stealthily detect a magic packet and establish reverse or bind shells; Elastic attributes it to the Chinese group Red Menshen and documents multi-year use against telecommunications, government, logistics, and education targets in the Middle East and Asia. The report details the attack lifecycle (installation in /dev/shm, process spoofing, PID files, BPF filters, iptables trickery), anti-forensics techniques, historical sample comparisons, IOCs (multiple SHA-256s, filenames, process names), detection artifacts (EQL hunting queries, Elastic detection rules, YARA signatures), and tools (scanner, config extractor, client POC) to assist defenders in identifying and responding to infections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.