logo

Red Menshen’s Sleeper Cells Hijack the Global Telecom “Nervous System”

ID: 0ee73fb1-24b1-5a40-af4d-d30b9b73338f

STIX ID: report--0ee73fb1-24b1-5a40-af4d-d30b9b73338f

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-02

Date Updated: 2026-04-23

Author: Ddos

...
...

Rapid7 Labs reports that a China-linked APT dubbed Red Menshen has stealthily implanted a kernel-level Linux backdoor called BPFdoor into telecom infrastructure to enable long-term espionage; the implant leverages BPF to inspect traffic in-kernel, uses magic-packet and HTTPS-concealed triggers, mimics legitimate hardware and container services, and can expose subscriber identifiers, mobility events, and signaling protocols at population scale.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.