A recently discovered backdoor malware called BPFdoor has been stealthily targeting Linux and Solaris systems without being detected for over five years. BPFdoor is a Linux/Unix backdoor that allows threat actors to remotely log into a Linux shell to gain full access to a compromised device.
The malware doesn't need to open ports, can't be stopped by firewalls, and can respond to commands from any IP address on the web, making it an ideal tool for corporate espionage and persistent attacks.
See also: Zyxel fixes critical firewall flaws

Analysis of "magic" packages
BPFdoor is a passive backdoor, meaning it can listen on one or more ports for incoming packets from one or more hosts, which attackers can use to send commands remotely to the compromised network.
The malware uses a Berkeley packet filter (BPF in the backdoor's name), which operates at the network layer interface and can see all network traffic and send packets to any destination.
Due to its placement at such a low level, BPF does not comply with any firewall rules.
It has versions for Linux and Solaris SPARC, but could also be ported to BSD, BleepingComputer learned from Craig Rowland, founder of Sandfly Security, a company that offers an agentless solution for protecting Linux systems.
Security researcher Kevin Beaumont, who posted on BPFdoor, told BleepingComputer that operators use a "magic" password to control the implant's actions.
See also: Eternity Project: The malware kit that offershacking
BPFdoor only analyzes ICMP, UDP, and TCP packets, checking them for a specific data value, as well as a password for the latter two packet types.
What makes BPFDoor stand out is that it can monitor any port for the magic packet, even if those ports are used by other legitimate services, such as webservers, FTP, or SSH.
If the TCP and UDP packets have the correct "magic" data and a correct password, the backdoor is activated by executing a supported command, such as setting a bind or reverse shell.

Beaumont told us that ICMP packets do not require a password, which allowed him to scan the Internet for BPFdoor implants using the ping function.
The researcher was able to find BPFdoor activity in networks of organizations in various regions, mainly in the US, South Korea, Hong Kong, Turkey, India, Vietnam, and Myanmar.
Surprisingly, he discovered 11 Speedtest servers infected with BPFdoor. The researcher said it is unclear how these machines were compromised, especially since they run on closed-source software.
Made in China?
Researchers BleepingComputer spoke to about BPFdoor did not attribute the malware to any particular threat actor. But in an annual report on cyber threats, researchers from PricewaterhouseCoopers (PwC) note that they found the BPFdoor implant during an incident response engagement.
PwC attributed the intrusion to a China-, which they track as Red Menshen (formerly Red Dev 18), who was using BPFdoor on “telecommunications providers across the Middle East and Asia, as well as government, education and logistics entities.”
See also: Ukrainian man jailed for selling thousands of credentials on the dark web
During the investigations, PwC researchers discovered that in the post-exploitation stage of their attacks, Red Menshen used customized variants of the Mangzamel backdoor and the Gh0st remote access tool (RAT) along with open source tools such as Mimikatz (for credential) and the Metasploit penetration testing suite, for lateral movement on Windows systems.
The researchers note that Red Menshen activity occurs within a nine-hour time frame, between 01:00 and 10:00 UTC, which may align with local work hours.
Information source: bleepingcomputer.com
