BPFDoor’s Hidden Controller Targets AMEA Sectors (Campaign)
ID: 08833902-aeb5-5150-86fa-de040832c0a8
STIX ID: report--08833902-aeb5-5150-86fa-de040832c0a8
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-04-14
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Trend Micro uncovered BPFDoor, a previously unseen Linux backdoor controller attributed to the state‑sponsored APT Earth Bluecrow (Red Menshen). The backdoor leverages Berkeley Packet Filter (BPF) magic packets to silently activate and bypass firewalls, supports reverse shells, port redirection, and encrypted TCP/UDP/ICMP communications authenticated via a salted MD5 check, and has been observed enabling lateral movement and long‑term persistence against telecommunications, financial, and retail targets across South Korea, Malaysia, Myanmar, Egypt, and Hong Kong.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
