BPFDoor Variants Hide with Stateless C2 and ICMP Relay Tactics
ID: 4056a904-5a54-51d5-82f0-cdaed75c0311
STIX ID: report--4056a904-5a54-51d5-82f0-cdaed75c0311
Feed Name: GBHackers
Rapid7 Labs discovered seven new BPFDoor Linux backdoor variants that embed C2 and shell access in kernel-level BPF filters to remain stealthy in large networks, using features like a Hidden IP (HIP) field, ICMP-based tunnels/relays, HTTP tunneling with a “magic ruler”, and active beacons over HTTPS; the report describes their lateral movement, anti-forensics, detection indicators (hardcoded ICMP sequence numbers, unusual BPF filters), and provides YARA/Suricata rules and triage scripts to help defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
