Red Menshen’s Sleeper Cells Hijack the Global Telecom “Nervous System”
ID: 0ee73fb1-24b1-5a40-af4d-d30b9b73338f
STIX ID: report--0ee73fb1-24b1-5a40-af4d-d30b9b73338f
Feed Name: securityonline.info
Threat Score
Rapid7 Labs reports that a China-linked APT dubbed Red Menshen has stealthily implanted a kernel-level Linux backdoor called BPFdoor into telecom infrastructure to enable long-term espionage; the implant leverages BPF to inspect traffic in-kernel, uses magic-packet and HTTPS-concealed triggers, mimics legitimate hardware and container services, and can expose subscriber identifiers, mobility events, and signaling protocols at population scale.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
