From bytecode to bytes: automated magic packet generation
ID: f6f30a39-fca4-5666-9faa-b692c0de0e96
STIX ID: report--f6f30a39-fca4-5666-9faa-b692c0de0e96
Feed Name: Cloudflare Blog
This research post analyzes BPFDoor, a kernel-level Linux backdoor that hides in classic BPF socket programs and is used by China-linked APTs (Red Menshen/Earth Bluecrow) for long-term, stealthy access to telecommunications, education, and government targets; it demonstrates an automated method using symbolic execution with Z3 and scapy to derive the exact network packets that trigger BPF-based implants and provides an open-source tool (filterforge) to automate deconstruction and detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
