logo

Hackers Implant Stealthy BPFdoor Backdoors in Telecom Networks for Persistent Access

ID: 68d48e05-df9e-5b9e-ab69-f3150f78b8f5

STIX ID: report--68d48e05-df9e-5b9e-ab69-f3150f78b8f5

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-03-27

Date Updated: 2026-04-22

Author: Divya

...
...

A China-linked APT dubbed Red Menshen is conducting a stealthy espionage campaign against global telecommunications networks by deploying a Linux kernel backdoor called BPFdoor. The malware abuses BPF to install hidden kernel filters that wait for magic packets (no open listening ports), monitors SCTP signaling used in 4G/5G to access SMS, subscriber identities and location data, and evades detection by mimicking hardware and container processes; operators also use CrossC2, TinyShell, custom keyloggers, and SSH brute-forcers to move from edge devices to core systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.