Researchers release tool to detect stealthy BPFDoor implants in critical infrastructure networks
ID: ac22f67a-bf6f-5533-9950-896abf647f86
STIX ID: report--ac22f67a-bf6f-5533-9950-896abf647f86
Feed Name: Help Net Security
Rapid7 researchers detail BPFDoor, a kernel-level Linux implant used by the China-linked APT Red Menshen (and associated activity from groups like Salt Typhoon) to target telecommunications, finance, and retail organizations. BPFDoor abuses Berkeley Packet Filter functionality to inspect packets in-kernel and remains dormant until triggered by specially crafted "magic" packets (including within HTTPS or via ICMP), allowing highly stealthy persistence; Rapid7 released a scanning script to detect known variants but warns about false negatives and evolving, harder-to-detect samples.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
