Threat reportAPTTL-2026-0087
BPFDoor — Chinese Nation-State Linux Backdoor Using Berkeley Packet Filters for Covert C2 Activation
BPFDoor — Chinese Nation-State Linux Backdoor Using Berkeley (TL-2026-0087) is a critical-severity advanced persistent threat campaign, first published 2026-02-15. It is attributed to Red Menshen (China) with high confidence, maps to 23 MITRE ATT&CK techniques (T1005, T1014, T1016), and is covered by 9 detection rules and 33 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 23MITRE ATT&CK
- Actors
- 1Red Menshen
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 33Indicators of compromise
Key facts for TL-2026-0087
- Threat ID
- TL-2026-0087
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution
- Red Menshen
- Attribution confidence
- HIGH
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- Telecommunications, Government, Finance, Logistics, Education, Retail
- Target regions
- South Korea, Hong Kong, Myanmar, Malaysia, Egypt, Middle East, Asia, Africa
- Detection rules
- 9
- Indicators of compromise
- 33
Malware and tooling in BPFDoor — Chinese Nation-State Linux Backdoor Using Berkeley
Malware and tooling: BPFDoor
How BPFDoor — Chinese Nation-State Linux Backdoor Using Berkeley works
BPFDoor is a stealthy Linux backdoor leveraging Berkeley Packet Filters (BPF) for covert C2 activation, attributed to Chinese nation-state APT Red Menshen (Earth Bluecrow). Active since at least 2017 with code lineage traced to ~2006 sniffdoor, BPFDoor intercepts magic packets on any port before firewall processing, enabling invisible persistent access to telecommunications, government, finance, and logistics targets across Asia, Middle East, and Africa. Version 2 introduced SSL encryption, SOCK_DGRAM evasion, and removed /dev/shm residency. Linked to the April 2025 SK Telecom breach affecting 23 million subscribers.
BPFDoor is a highly sophisticated passive Linux backdoor designed for long-term espionage operations by Chinese nation-state threat actors. The malware's core innovation is its abuse of Berkeley Packet Filters (BPF) — a kernel-level packet filtering technology — to intercept specially crafted 'magic packets' on ANY port before the Linux firewall (netfilter/iptables) processes them. This means BPFDoor activates even on hosts with strict firewall rules blocking unauthorized traffic.
The backdoor operates in three modes: (1) bind shell — opens a local port with iptables redirect for attacker connection, (2) reverse shell — connects back to attacker infrastructure, and (3) port reuse — hijacks existing legitimate service connections (e.g., connecting through port 443 where nginx is running). Magic packets can arrive via TCP, UDP, or ICMP protocols with configurable magic byte sequences (default TCP: 0x5293).
BPFDoor's anti-forensics suite includes: process name masquerading (random selection from common daemon names like /sbin/udevd, dbus-daemon, avahi-daemon), binary self-deletion from disk while remaining memory-resident, environment variable wiping to defeat incident response, timestomping with a hardcoded 2008 epoch value, and PID file creation at /var/run/ for mutex locking.
Version 1 (2017-2023) resided in /dev/shm ramdisk, used SOCK_RAW sockets, RC4 encryption, and random process name selection from a 10-name list. Version 2 (2024-present) eliminated /dev/shm residency, switched to SOCK_DGRAM|SOCK_CLOEXEC sockets to evade raw socket detection, implemented SSL with embedded certificates replacing RC4, uses fixed (environment-matched) process names, and incorporates salted MD5 password hashes with the constant salt 'I5*AYbs@LdaWbsO'.
Code lineage analysis by HaxRob traced BPFDoor's origins to 'sniffdoor' (~2006-2007), which shared code from bindtty.c and the WNPS rootkit. The sniffdoor developer was associated with the NCPH Group, some members of which later became linked to APT41. An intermediate variant 'NotBPFDoor' (2016, submitted from Hong Kong) bridges sniffdoor and modern BPFDoor, adding boot persistence and configuration menus later stripped in production versions.
A dedicated controller binary discovered by Trend Micro in 2025 enables operators to send magic packets with password authentication, select reverse/bind shell modes, choose TCP/UDP/ICMP protocols, and customize magic byte sequences per target. The controller has never been observed outside Earth Bluecrow operations.
The April 2025 SK Telecom breach — the largest telecom breach in South Korean history affecting 23 million subscribers — was linked to BPFDoor. Investigators found 12+ malware strains on SKT's home subscriber server, with initial access potentially via exploited Ivanti VPN vulnerabilities. The breach exposed USIM authentication keys enabling SIM swapping attacks, with estimated financial impact of $5 billion over three years.
MITRE ATT&CK techniques used in TL-2026-0087
collection
T1005 Data from Local System; T1213 Data from Information Repositories
defense-evasion
T1014 Rootkit; T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1070.004 File Deletion; T1070.006 Timestomp; T1205.001 Port Knocking; T1564.010 Process Argument Spoofing
discovery
T1016 System Network Configuration Discovery
lateral-movement
credential-access
T1040 Network Sniffing; T1110 Brute Force
execution
privilege-escalation
T1068 Exploitation for Privilege Escalation
command-and-control
T1095 Non-Application Layer Protocol; T1105 Ingress Tool Transfer; T1572 Protocol Tunneling; T1573.002 Asymmetric Cryptography
initial-access
T1190 Exploit Public-Facing Application
persistence
defense-impairment
T1685.006 Clear Linux or Mac System Logs; T1686 Disable or Modify System Firewall
Remediation for BPFDoor — Chinese Nation-State Linux Backdoor Using Berkeley
Immediate actions
- Hunt for BPFDoor using Sandfly agentless scanner or Elastic BPFDoor scanner on all Linux infrastructure
- Check for processes with deleted binaries: ls -alR /proc/*/exe 2>/dev/null | grep deleted
- Inspect for unexpected BPF filters: ss -0pb | grep -v systemd
- Search for suspicious PID files in /var/run/ matching known mutex patterns (haldrund.pid, lldpad.lock, system.pid)
- Verify no unauthorized binaries exist in /dev/shm/
- Review iptables rules for unexpected REDIRECT rules on ports 42391-43391
Workarounds
- Block ICMP/UDP to non-essential services at network perimeter (reduces magic packet delivery vectors but does not prevent TCP-based activation on open ports)
- Enable auditd socket monitoring: auditctl -a exit,always -F arch=b64 -S socket -F a0=17
- Monitor setsockopt with SO_ATTACH_FILTER: auditctl -a exit,always -F arch=b64 -S setsockopt -F a2=26
Longer-term hardening
- Deploy agentless Linux intrusion detection (Sandfly) for continuous BPFDoor hunting
- Monitor raw socket and AF_PACKET socket creation via auditd rules
- Implement process integrity monitoring — flag processes with wiped environments or masqueraded names
- Deploy network deep packet inspection for magic packet sequences (default TCP: 0x5293)
- Restrict CAP_NET_RAW and CAP_BPF capabilities to authorized processes only
- Audit all Ivanti VPN instances for exploitation indicators
- Implement SIM protection services for telecom subscribers
Weaknesses (CWE) in BPFDoor — Chinese Nation-State Linux Backdoor Using Berkeley
Timeline of BPFDoor — Chinese Nation-State Linux Backdoor Using Berkeley
- sniffdoor v1.0 developed (~2006-2007) — precursor to BPFDoor sharing bindtty.c code, PTY handling, and magic packet concept. Developer associated with NCPH Group and xsec.org community. Source: https://haxrob.net/bpfdoor-past-and-present-part-1/
- NotBPFDoor — early BPFDoor variant without BPF filters — uploaded to VirusTotal from Hong Kong. Uses semaphore mutex (key 0x55715570 = epoch June 5, 2015), single hardcoded process name, optional persistence. Source: https://haxrob.net/bpfdoor-past-and-present-part-1/
- BPFDoor Version 1 begins active deployment targeting telecommunications and government infrastructure. Uses /dev/shm ramdisk residency, SOCK_RAW sockets, RC4 encryption, random process name selection from 10 daemon names, hardcoded password 'justforfun'. Source: https://sandflysecurity.com/blog/bpfdoor-an-evasive-linux-backdoor-technical-analysis
- PwC Cyber Threat Intelligence documents BPFDoor in Year in Retrospect report, attributes to Red Menshen APT. Notes Monday-Friday 01:00-10:00 UTC operating pattern targeting telecommunications, government, logistics, education across Middle East and Asia. Source: PwC Cyber Threat Intelligence Retrospect Report 2022
- Kevin Beaumont publicly reveals BPFDoor existence via DoublePulsar blog, noting potentially thousands of instances deployed globally for years. Sandfly Security and Elastic Security Labs publish detailed technical analyses within days. Source: https://doublepulsar.com/bpfdoor-an-active-chinese-global-surveillance-tool-54b078f1a896
- Sandfly Security publishes comprehensive BPFDoor technical analysis covering BPF filter bytecode reverse engineering, anti-forensics techniques, process masquerading, environment wiping, and detection methodologies. Source: https://sandflysecurity.com/blog/bpfdoor-an-evasive-linux-backdoor-technical-analysis
- Elastic Security Labs releases BPFDoor scanner and configuration extractor tools, publishes YARA rules including Linux_Trojan_BPFDoor_5 for packet_loop function detection. Source: https://www.elastic.co/security-labs/a-peek-behind-the-bpfdoor
- BPFDoor Version 2 emerges with major evasion upgrades: SOCK_DGRAM|SOCK_CLOEXEC replaces SOCK_RAW (evades raw socket detection), SSL with embedded certificates replaces RC4, no /dev/shm residency, fixed environment-matched process names, salted MD5 password hashes. Source: https://haxrob.net/bpfdoor-past-and-present-part-2/
- SK Telecom detects abnormal activity at 11:20 PM local time. Investigators find unusual logs and deleted files on billing/monitoring servers. BPFDoor identified among 12+ malware strains on home subscriber server. 23 million subscribers' USIM data including authentication keys exfiltrated. Source: https://techcrunch.com/2025/05/08/a-timeline-of-south-korean-telco-giant-skts-data-breach/
- Trend Micro publishes analysis of previously undiscovered BPFDoor controller binary used by Earth Bluecrow. Controller supports TCP/UDP/ICMP magic packet delivery, password authentication, reverse/bind shell selection, configurable magic byte sequences, and encrypted sessions. Targets confirmed in South Korea, Hong Kong, Myanmar, Malaysia, Egypt. Source: https://www.trendmicro.com/en_us/research/25/d/bpfdoor-hidden-controller.html
- Sandfly Security publishes updated 2026 BPFDoor detection and hunting guide covering both Version 1 and Version 2. New Sandfly 5.5 detections decode open file descriptors to identify SOCK_DGRAM packet sniffers, improved process_running_sniffer_operating_ipv4_traffic module catches Version 2 evasion. Source: https://sandflysecurity.com/blog/bpfdoor-detection-analysis-and-hunting-tactics-on-linux
- As of 2026-05-29, BPFDoor remains active: Rapid7's March 26 2026 investigation found new stealthier variants (httpShell, icmpShell, HTTPS-embedded magic packets, ICMP relay C2) in live telecom networks. Red Menshen/Earth Bluecrow keeps operating with no takedown; no CVE applies since it is a post-exploitation backdoor, so ACTIVE stands.
Sources cited for BPFDoor — Chinese Nation-State Linux Backdoor Using Berkeley
- BPFDoor Detection, Analysis and Hunting Tactics on Linux (2026)
- BPFDoor - An Evasive Linux Backdoor Technical Analysis (2022)
- BPFDoor Part 1 - The Past (Code Origins & sniffdoor lineage)
- BPFDoor Part 2 - The Present (v2 Evasion Improvements)
- BPFDoor's Hidden Controller Used Against Asia, Middle East Targets
- A Peek Behind the BPFDoor - Elastic Security Labs
- BPFDoor — An Active Chinese Global Surveillance Tool (Kevin Beaumont)
- SK Telecom Data Breach Timeline — 23M Subscribers Affected
- PwC Cyber Threat Intelligence Year in Retrospect (BPFDoor Attribution)
- Detecting BPFDoor Backdoor Variants Abusing BPF Filters
- BPFDoor Scanner - Elastic Security Labs
- BPFDoor Configuration Extractor - Elastic Security Labs
Detection coverage for TL-2026-0087
As of 2026-02-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0087 across Splunk SPL, Microsoft KQL and Sigma, covering 33 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.