logo

China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy via Telecom Networks

ID: 25f891b7-b67c-5dd2-8cd8-01c1733db2ae

STIX ID: report--25f891b7-b67c-5dd2-8cd8-01c1733db2ae

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-03-26

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Rapid7 attributes a long-running, highly stealthy espionage campaign to a China-linked threat cluster known as Red Menshen (aka Earth Bluecrow, DecisiveArchitect, Red Dev 18) that implants kernel-level Linux backdoors—most notably BPFDoor—into telecom and enterprise infrastructure to gain persistent, low-noise visibility and access; the actor leverages exploited edge services (VPNs, firewalls, web-facing platforms), deploys cross-platform post-exploitation frameworks (e.g., CrossC2, Sliver), credential-harvesting tools, and novel evasion techniques (e.g., hiding triggers inside HTTPS at fixed offsets, SCTP support, ICMP communications) to monitor subscriber behavior, enable lateral movement, and maintain long-term persistence in 4G/5G and enterprise environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.