China Upgrades the Backdoor It Uses to Spy on Telcos Globally
ID: 72ffb045-29bc-5442-a7be-d894a115164b
STIX ID: report--72ffb045-29bc-5442-a7be-d894a115164b
Feed Name: Dark Reading
Researchers report that Chinese APT "Red Menshen" has upgraded the BPFdoor Linux kernel backdoor to more stealthily maintain persistence and control within global telecommunications, government, and critical infrastructure networks. Enhancements include detecting an HTTPS activation phrase at the 26th byte offset, an ICMP-based control channel that routes commands to specific implants using a 0xFFFFFFFF marker, and process disguises tailored to HPE ProLiant and Kubernetes environments, enabling covert, high-fidelity reconnaissance and lateral control across victim networks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
