logo

BPFdoor in Telecom Networks: The FCC Is Securing the Edge, but China’s Hackers Are Already Past It

ID: 9a036c71-5d44-5f9b-bb18-489e399e2412

STIX ID: report--9a036c71-5d44-5f9b-bb18-489e399e2412

Feed Name: Security Boulevard

Threat Score
90/100

Date Published: 2026-03-26

Date Updated: 2026-04-22

Author: Mike Bell

...
...

Rapid7 / Suzu Labs analysis describes BPFdoor, a stealthy Linux kernel backdoor used by China-linked Red Menshen to maintain long-term, undetectable access inside telecom signaling cores; newer variants embed activation triggers in HTTPS traffic and filter SCTP (4G/5G signaling), enabling observation of subscriber authentication and lateral movement via ICMP tunnels. The report contrasts this kernel-level foothold with prior IT-layer campaigns (Salt Typhoon), notes a lack of underground trading (suggesting state-level operation), and provides detection and mitigation guidance focused on kernel-level visibility (BPF filter enumeration, raw socket auditing, process integrity checks, SCTP monitoring, and use of community scanners/YARA rules).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.