BPFdoor in Telecom Networks: The FCC Is Securing the Edge, but China’s Hackers Are Already Past It
ID: 9a036c71-5d44-5f9b-bb18-489e399e2412
STIX ID: report--9a036c71-5d44-5f9b-bb18-489e399e2412
Feed Name: Security Boulevard
Rapid7 / Suzu Labs analysis describes BPFdoor, a stealthy Linux kernel backdoor used by China-linked Red Menshen to maintain long-term, undetectable access inside telecom signaling cores; newer variants embed activation triggers in HTTPS traffic and filter SCTP (4G/5G signaling), enabling observation of subscriber authentication and lateral movement via ICMP tunnels. The report contrasts this kernel-level foothold with prior IT-layer campaigns (Salt Typhoon), notes a lack of underground trading (suggesting state-level operation), and provides detection and mitigation guidance focused on kernel-level visibility (BPF filter enumeration, raw socket auditing, process integrity checks, SCTP monitoring, and use of community scanners/YARA rules).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
