The RedMenshen APT team is rapidly evolving the BPFDoor Malware.
Most threat groups that distribute malware seek the greatest possible efficiency in their malicious efforts, which is why many of the systems they target run Microsoft's Windows operating system.
However, APT threat actors—including those running ransomware campaigns—are more interested in keeping their presence undetected on their victims’ systems. In recent years, these groups have expanded their target scope to include cloud servers and systems running Linux and other non-Windows operating systems, according to cybersecurity firm Trend Micro.
In the cloud, this included ransomware groups targeting systems running VMware ESXi servers and a number of variants of the Mirai botnet. Additionally, the infamous Sandworm malware , developed by the Russian military intelligence unit GRU, was used against network routers running Linux.
Red Menshen is another APT group that is rapidly evolving the BPFDoor backdoor malware to target systems running Linux or Solaris. This group, also known as DecisiveArchitect and Red Dev 18, has improved the use of the Berkeley Packet Filter (BPF), a legitimate tool that allows programs running on certain operating systems to analyze network traffic.
Red Menshen targets telecommunications and other industries, mainly in Turkey and Hong Kong.

See also: IT employee jailed for posing as a ransomware group and blackmailing his employer
It is difficult to catch
For the threat actor, BPF makes it harder to detect BPFDoor, according to Fernando Merces, a senior threat researcher at Trend Micro. The technology “allows programs to attach network filters to an open socket used by threat actors behind BPFDoor to bypass inbound firewall rules and similar network protection solutions on Linux and Solaris operating systems (OS),” Merces wrote in a report.
Neither operating system is a leader in its field. Of the total global operating system market, Windows accounts for more than 28%, while Linux has 1.3%, according to StatCounter. There are more than 44,000 companies using Solaris, which has about a 0.9% share of the operating system space, Enlyft reports.
While their market share may be small, Linux and Solaris are used by companies of all sizes and across a wide range of industries, which explains why an APT group like Red Menshen is making an effort to target these systems. Trend Micro tracks two versions: one for Linux systems and one for servers running Solaris. Merces added that the group is aggressively improving its capabilities.
There are now six times more instructions in the malware's BPF filters than were found in two samples last year.
Red Menshen, a Chinese threat, uses BPF—the Linux equivalent is called Linux Socket Filtering (LSF)—to load packet filters into the Linux kernel. The filters allow attackers to trigger the malware with a single network packet, as it reaches the kernel's BPF before it reaches the firewall, which would otherwise block it. BPFDoor then opens a reverse shell that accepts commands from the attacker and gives the malware the root privileges it needs to operate.
See also: JumpCloud: Hacking attack led to breach

See also: Hackers are actively exploiting two ColdFusion vulnerabilities
More variations appearing
Malware samples — one of them called Variant A — found before 2023 contained the same BPF program and included 30 instructions. Trend Micro worked with four samples this year and found more variants. Variant B contained 39 instructions, which may indicate that the BPFDoor developers wanted another way to activate the backdoor after reports shed light on how the previous variant worked, Merces wrote.
Variant C has about six times the number of commands – 205 – while variant D has 229. Deep Instinct, a cybersecurity firm, found another variant that Trend Micro refers to as Variant E.
The use of embedded BPF bytecode in malware will cause headaches for organizations and security analysts. Although it is not widely used in malware and there are not many tools for analyzing and debugging such bytecode, it can give attackers full access to an infected system.
According to Trend Micro, network defenders need to update their rules to address this trend, and malware analysts need to look more closely at BPF filters in malware.
Information source: securityboulevard.com
