logo

Researchers release tool to detect stealthy BPFDoor implants in critical infrastructure networks

ID: ac22f67a-bf6f-5533-9950-896abf647f86

STIX ID: report--ac22f67a-bf6f-5533-9950-896abf647f86

Feed Name: Help Net Security

Threat Score
85/100

Date Published: 2026-03-26

Date Updated: 2026-04-28

Author: Zeljka Zorz

...
...

Rapid7 researchers detail BPFDoor, a kernel-level Linux implant used by the China-linked APT Red Menshen (and associated activity from groups like Salt Typhoon) to target telecommunications, finance, and retail organizations. BPFDoor abuses Berkeley Packet Filter functionality to inspect packets in-kernel and remains dormant until triggered by specially crafted "magic" packets (including within HTTPS or via ICMP), allowing highly stealthy persistence; Rapid7 released a scanning script to detect known variants but warns about false negatives and evolving, harder-to-detect samples.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.