logo

China Upgrades the Backdoor It Uses to Spy on Telcos Globally

ID: 72ffb045-29bc-5442-a7be-d894a115164b

STIX ID: report--72ffb045-29bc-5442-a7be-d894a115164b

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2026-03-27

Date Updated: 2026-04-22

Author: Nate Nelson

...
...

Researchers report that Chinese APT "Red Menshen" has upgraded the BPFdoor Linux kernel backdoor to more stealthily maintain persistence and control within global telecommunications, government, and critical infrastructure networks. Enhancements include detecting an HTTPS activation phrase at the 26th byte offset, an ICMP-based control channel that routes commands to specific implants using a 0xFFFFFFFF marker, and process disguises tailored to HPE ProLiant and Kubernetes environments, enabling covert, high-fidelity reconnaissance and lateral control across victim networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.