logo

From bytecode to bytes: automated magic packet generation

ID: f6f30a39-fca4-5666-9faa-b692c0de0e96

STIX ID: report--f6f30a39-fca4-5666-9faa-b692c0de0e96

Feed Name: Cloudflare Blog

Threat Score
85/100

Date Published: 2026-04-08

Date Updated: 2026-04-27

Author: Axel Boesenach

...
...

This research post analyzes BPFDoor, a kernel-level Linux backdoor that hides in classic BPF socket programs and is used by China-linked APTs (Red Menshen/Earth Bluecrow) for long-term, stealthy access to telecommunications, education, and government targets; it demonstrates an automated method using symbolic execution with Z3 and scapy to derive the exact network packets that trigger BPF-based implants and provides an open-source tool (filterforge) to automate deconstruction and detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.