China-linked Red Menshen APT deploys stealthy BPFDoor implants in telecom networks
ID: fa2cb820-ae88-59bb-bbf4-065b8879cfe6
STIX ID: report--fa2cb820-ae88-59bb-bbf4-065b8879cfe6
Feed Name: Security Affairs
Threat Score
Rapid7 and reporting indicate a China-linked APT dubbed Red Menshen has conducted a long-term espionage campaign (since at least 2021) against telecommunications providers in the Middle East and Asia, deploying highly stealthy kernel-level BPFdoor/eBPF implants and related tooling to surveil signaling, subscriber data, and government communications while remaining difficult to detect; the report includes technical analysis, evolved variants, stealth techniques, and IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
