logo

Red Menshen APT Uses BPFdoor for Long-Term Espionage in Telecom Networks

ID: 69e3c819-d4dc-5e0c-b545-7454be3d91ae

STIX ID: report--69e3c819-d4dc-5e0c-b545-7454be3d91ae

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-03-26

Date Updated: 2026-03-31

...
...

Red Menshen, a China-linked APT, has been conducting long-term espionage against global telecommunications networks since at least 2021 using a stealthy Linux kernel backdoor called BPFdoor that passively inspects traffic and triggers on specially crafted packets; its kernel-level operation makes detection difficult and has prompted efforts to develop detection tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.