HomeSecurityRed Menshen: Using BPFDoor for espionage through telecommunications networks

Red Menshen: Use of BPFDoor for espionage via telecommunications networks

A long-running and ongoing campaign, attributed to Chinese hackers Red Menshen, has been embedded in telecommunications networks to conduct espionage against government networks. The activity includes introducing and maintaining covert access mechanisms into critical environments.

Red Menshen BPFDoor

The group, also tracked as Earth Bluecrow, DecisiveArchitect and Red Dev 18, has a history of attacking telecom providers in the Middle East and Asia since 2021. Rapid7 described the hidden access mechanisms as “ some of the most covert digital sleeper cells ” ever encountered in telecommunications networks.

The malicious campaign relies on the use of kernel-level implants, passive backdoors, credential-harvesting utilities and cross-platform command frameworks, giving the threat actor the ability to persist for long periods on networks of interest. One of the most recognized tools in the Red Menshen group's arsenal is a Linux backdoor called BPFDoor.

See also: GitHub Phishing: Fake OpenClaw tokens to steal crypto wallets

“Unlike conventional malware, BPFDoor does not expose listening ports or maintain visible command-and-control channels,” Rapid7 Labs said in a report. “Instead, it exploits the functionality of the Berkeley Packet Filter (BPF) to inspect network traffic directly within the kernel and only activates when it receives a specially crafted activation packet.”

“There is no persistent listener or obvious beaconing. The result is a hidden trap embedded within the operating system itself“.

Red Menshen: How BPFDoor distribution attacks work

The attack chains begin with the threat actor targeting internet-exposed edge infrastructure and services , such as VPN devices, firewalls, and internet-exposed platforms connected to Ivanti, Cisco, Juniper Networks, Fortinet, VMware, Palo Alto Networks, and Apache Struts . This targeting is done to gain initial access.

Red Menshen: Use of BPFDoor for espionage via telecommunications networks

After successfully gaining access, Linux-compatible beacon frameworks , such as CrossC2 , are deployed. Sliver , TinyShell (a Unix backdoor), keyloggers , and brute-force tools are also installed to facilitate credential harvesting and lateral movement.

BPFDoor plays a central role in Red Menshen's operations . It has two distinct components:

  • One is a passive backdoor that is deployed on the compromised Linux system to inspect incoming traffic for a predefined “magic” packet by installing a BPF filter and creating a remote shell upon receipt of such a packet.
  • The other core component of the framework is a controller managed by the attacker and is responsible for sending the specially crafted packets.

“The controller is also designed to operate within the victim’s environment,” Rapid7 explained. “In this mode, it can impersonate legitimate system processes and trigger additional implants on internal computers by sending activation packets or opening a local listener to receive shell connections, essentially allowing controlled lateral movement between compromised systems.”

See also: WebRTC Skimmer bypasses CSP and steals payment data

Some BPFDoor files have been found to support Stream Control Transmission Protocol (SCTP), potentially allowing an adversary to monitor protocols native to telecommunications and gain visibility into subscriber behavior and location, and even track specific individuals.

These aspects show that BPFDoor's functionality goes beyond a hidden Linux backdoor. "BPFDoor acts as an access layer embedded within the telecommunications backbone, providing long-term, silent visibility into critical network operations," the security vendor added.

A previously unpublished variant of BPFDoor incorporates architectural changes to make it more invisible for extended periods in modern enterprise and telecommunications environments. These include hiding the activation packet within seemingly legitimate HTTPS traffic and introducing a new parsing mechanism that ensures that the string “9999” appears at a fixed byte offset.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Red Menshen: Use of BPFDoor for espionage via telecommunications networks

This camouflage, in turn, allows the magic packet to remain hidden within HTTPS traffic and avoid causing offsets in the position of the data within the request. It also allows the implant to always check for the marker at a specific byte offset and, if present, interpret it as an activation command.

The newly discovered sample also exhibits a “lightweight communication mechanism” that uses the Internet Control Message Protocol (ICMP) to interact between two infected hosts.

See also: Device code phishing attack has targeted 340+ organizations

“ Attackers are embedding implants deeper into the computing stack – targeting operating system kernels and infrastructure platforms rather than relying solely on user-space malware environments , Telecom – which combine bare-metal systems, virtualization layers, high-performance devices, and containerized 4G/5G cores – provide an ideal breeding ground for low-noise, long-term persistence. Combined with legitimate hardware services ” Rapid7 said. “ and container runtimes, implants can evade traditional endpoint monitoring and remain undetected for long periods of time .”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS