China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy via Telecom Networks
ID: 25f891b7-b67c-5dd2-8cd8-01c1733db2ae
STIX ID: report--25f891b7-b67c-5dd2-8cd8-01c1733db2ae
Feed Name: The Hacker News
Rapid7 attributes a long-running, highly stealthy espionage campaign to a China-linked threat cluster known as Red Menshen (aka Earth Bluecrow, DecisiveArchitect, Red Dev 18) that implants kernel-level Linux backdoors—most notably BPFDoor—into telecom and enterprise infrastructure to gain persistent, low-noise visibility and access; the actor leverages exploited edge services (VPNs, firewalls, web-facing platforms), deploys cross-platform post-exploitation frameworks (e.g., CrossC2, Sliver), credential-harvesting tools, and novel evasion techniques (e.g., hiding triggers inside HTTPS at fixed offsets, SCTP support, ICMP communications) to monitor subscriber behavior, enable lateral movement, and maintain long-term persistence in 4G/5G and enterprise environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
