logo

BPFDoor Variants Hide with Stateless C2 and ICMP Relay Tactics

ID: 4056a904-5a54-51d5-82f0-cdaed75c0311

STIX ID: report--4056a904-5a54-51d5-82f0-cdaed75c0311

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-04-07

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Rapid7 Labs discovered seven new BPFDoor Linux backdoor variants that embed C2 and shell access in kernel-level BPF filters to remain stealthy in large networks, using features like a Hidden IP (HIP) field, ICMP-based tunnels/relays, HTTP tunneling with a “magic ruler”, and active beacons over HTTPS; the report describes their lateral movement, anti-forensics, detection indicators (hardcoded ICMP sequence numbers, unusual BPF filters), and provides YARA/Suricata rules and triage scripts to help defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.