Red Menshen APT Uses BPFdoor for Long-Term Espionage in Telecom Networks
ID: 69e3c819-d4dc-5e0c-b545-7454be3d91ae
STIX ID: report--69e3c819-d4dc-5e0c-b545-7454be3d91ae
Feed Name: ThreatCluster
Threat Score
Red Menshen, a China-linked APT, has been conducting long-term espionage against global telecommunications networks since at least 2021 using a stealthy Linux kernel backdoor called BPFdoor that passively inspects traffic and triggers on specially crafted packets; its kernel-level operation makes detection difficult and has prompted efforts to develop detection tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
