Threat reportAPTTL-2026-0087

BPFDoor — Chinese Nation-State Linux Backdoor Using Berkeley Packet Filters for Covert C2 Activation

criticalACTIVE

BPFDoor — Chinese Nation-State Linux Backdoor Using Berkeley (TL-2026-0087) is a critical-severity advanced persistent threat campaign, first published 2026-02-15. It is attributed to Red Menshen (China) with high confidence, maps to 23 MITRE ATT&CK techniques (T1005, T1014, T1016), and is covered by 9 detection rules and 33 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
23MITRE ATT&CK
Actors
1Red Menshen
Detection rules
9SPL · KQL · Sigma
IOCs
33Indicators of compromise

Key facts for TL-2026-0087

Threat ID
TL-2026-0087
Severity
CRITICAL
Status
ACTIVE
Category
APT
First published
Last reviewed
Attribution
Red Menshen
Attribution confidence
HIGH
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
Telecommunications, Government, Finance, Logistics, Education, Retail
Target regions
South Korea, Hong Kong, Myanmar, Malaysia, Egypt, Middle East, Asia, Africa
Detection rules
9
Indicators of compromise
33

Malware and tooling in BPFDoor — Chinese Nation-State Linux Backdoor Using Berkeley

Malware and tooling: BPFDoor

How BPFDoor — Chinese Nation-State Linux Backdoor Using Berkeley works

BPFDoor is a stealthy Linux backdoor leveraging Berkeley Packet Filters (BPF) for covert C2 activation, attributed to Chinese nation-state APT Red Menshen (Earth Bluecrow). Active since at least 2017 with code lineage traced to ~2006 sniffdoor, BPFDoor intercepts magic packets on any port before firewall processing, enabling invisible persistent access to telecommunications, government, finance, and logistics targets across Asia, Middle East, and Africa. Version 2 introduced SSL encryption, SOCK_DGRAM evasion, and removed /dev/shm residency. Linked to the April 2025 SK Telecom breach affecting 23 million subscribers.

BPFDoor is a highly sophisticated passive Linux backdoor designed for long-term espionage operations by Chinese nation-state threat actors. The malware's core innovation is its abuse of Berkeley Packet Filters (BPF) — a kernel-level packet filtering technology — to intercept specially crafted 'magic packets' on ANY port before the Linux firewall (netfilter/iptables) processes them. This means BPFDoor activates even on hosts with strict firewall rules blocking unauthorized traffic.

The backdoor operates in three modes: (1) bind shell — opens a local port with iptables redirect for attacker connection, (2) reverse shell — connects back to attacker infrastructure, and (3) port reuse — hijacks existing legitimate service connections (e.g., connecting through port 443 where nginx is running). Magic packets can arrive via TCP, UDP, or ICMP protocols with configurable magic byte sequences (default TCP: 0x5293).

BPFDoor's anti-forensics suite includes: process name masquerading (random selection from common daemon names like /sbin/udevd, dbus-daemon, avahi-daemon), binary self-deletion from disk while remaining memory-resident, environment variable wiping to defeat incident response, timestomping with a hardcoded 2008 epoch value, and PID file creation at /var/run/ for mutex locking.

Version 1 (2017-2023) resided in /dev/shm ramdisk, used SOCK_RAW sockets, RC4 encryption, and random process name selection from a 10-name list. Version 2 (2024-present) eliminated /dev/shm residency, switched to SOCK_DGRAM|SOCK_CLOEXEC sockets to evade raw socket detection, implemented SSL with embedded certificates replacing RC4, uses fixed (environment-matched) process names, and incorporates salted MD5 password hashes with the constant salt 'I5*AYbs@LdaWbsO'.

Code lineage analysis by HaxRob traced BPFDoor's origins to 'sniffdoor' (~2006-2007), which shared code from bindtty.c and the WNPS rootkit. The sniffdoor developer was associated with the NCPH Group, some members of which later became linked to APT41. An intermediate variant 'NotBPFDoor' (2016, submitted from Hong Kong) bridges sniffdoor and modern BPFDoor, adding boot persistence and configuration menus later stripped in production versions.

A dedicated controller binary discovered by Trend Micro in 2025 enables operators to send magic packets with password authentication, select reverse/bind shell modes, choose TCP/UDP/ICMP protocols, and customize magic byte sequences per target. The controller has never been observed outside Earth Bluecrow operations.

The April 2025 SK Telecom breach — the largest telecom breach in South Korean history affecting 23 million subscribers — was linked to BPFDoor. Investigators found 12+ malware strains on SKT's home subscriber server, with initial access potentially via exploited Ivanti VPN vulnerabilities. The breach exposed USIM authentication keys enabling SIM swapping attacks, with estimated financial impact of $5 billion over three years.

MITRE ATT&CK techniques used in TL-2026-0087

collection

T1005 Data from Local System; T1213 Data from Information Repositories

defense-evasion

T1014 Rootkit; T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1070.004 File Deletion; T1070.006 Timestomp; T1205.001 Port Knocking; T1564.010 Process Argument Spoofing

discovery

T1016 System Network Configuration Discovery

lateral-movement

T1021.004 SSH

credential-access

T1040 Network Sniffing; T1110 Brute Force

execution

T1059.004 Unix Shell

privilege-escalation

T1068 Exploitation for Privilege Escalation

command-and-control

T1095 Non-Application Layer Protocol; T1105 Ingress Tool Transfer; T1572 Protocol Tunneling; T1573.002 Asymmetric Cryptography

initial-access

T1190 Exploit Public-Facing Application

persistence

T1505.003 Web Shell

defense-impairment

T1685.006 Clear Linux or Mac System Logs; T1686 Disable or Modify System Firewall

Remediation for BPFDoor — Chinese Nation-State Linux Backdoor Using Berkeley

Immediate actions

  • Hunt for BPFDoor using Sandfly agentless scanner or Elastic BPFDoor scanner on all Linux infrastructure
  • Check for processes with deleted binaries: ls -alR /proc/*/exe 2>/dev/null | grep deleted
  • Inspect for unexpected BPF filters: ss -0pb | grep -v systemd
  • Search for suspicious PID files in /var/run/ matching known mutex patterns (haldrund.pid, lldpad.lock, system.pid)
  • Verify no unauthorized binaries exist in /dev/shm/
  • Review iptables rules for unexpected REDIRECT rules on ports 42391-43391

Workarounds

  • Block ICMP/UDP to non-essential services at network perimeter (reduces magic packet delivery vectors but does not prevent TCP-based activation on open ports)
  • Enable auditd socket monitoring: auditctl -a exit,always -F arch=b64 -S socket -F a0=17
  • Monitor setsockopt with SO_ATTACH_FILTER: auditctl -a exit,always -F arch=b64 -S setsockopt -F a2=26

Longer-term hardening

  • Deploy agentless Linux intrusion detection (Sandfly) for continuous BPFDoor hunting
  • Monitor raw socket and AF_PACKET socket creation via auditd rules
  • Implement process integrity monitoring — flag processes with wiped environments or masqueraded names
  • Deploy network deep packet inspection for magic packet sequences (default TCP: 0x5293)
  • Restrict CAP_NET_RAW and CAP_BPF capabilities to authorized processes only
  • Audit all Ivanti VPN instances for exploitation indicators
  • Implement SIM protection services for telecom subscribers

Weaknesses (CWE) in BPFDoor — Chinese Nation-State Linux Backdoor Using Berkeley

CWE-829

Timeline of BPFDoor — Chinese Nation-State Linux Backdoor Using Berkeley

  • sniffdoor v1.0 developed (~2006-2007) — precursor to BPFDoor sharing bindtty.c code, PTY handling, and magic packet concept. Developer associated with NCPH Group and xsec.org community. Source: https://haxrob.net/bpfdoor-past-and-present-part-1/
  • NotBPFDoor — early BPFDoor variant without BPF filters — uploaded to VirusTotal from Hong Kong. Uses semaphore mutex (key 0x55715570 = epoch June 5, 2015), single hardcoded process name, optional persistence. Source: https://haxrob.net/bpfdoor-past-and-present-part-1/
  • BPFDoor Version 1 begins active deployment targeting telecommunications and government infrastructure. Uses /dev/shm ramdisk residency, SOCK_RAW sockets, RC4 encryption, random process name selection from 10 daemon names, hardcoded password 'justforfun'. Source: https://sandflysecurity.com/blog/bpfdoor-an-evasive-linux-backdoor-technical-analysis
  • PwC Cyber Threat Intelligence documents BPFDoor in Year in Retrospect report, attributes to Red Menshen APT. Notes Monday-Friday 01:00-10:00 UTC operating pattern targeting telecommunications, government, logistics, education across Middle East and Asia. Source: PwC Cyber Threat Intelligence Retrospect Report 2022
  • Kevin Beaumont publicly reveals BPFDoor existence via DoublePulsar blog, noting potentially thousands of instances deployed globally for years. Sandfly Security and Elastic Security Labs publish detailed technical analyses within days. Source: https://doublepulsar.com/bpfdoor-an-active-chinese-global-surveillance-tool-54b078f1a896
  • Sandfly Security publishes comprehensive BPFDoor technical analysis covering BPF filter bytecode reverse engineering, anti-forensics techniques, process masquerading, environment wiping, and detection methodologies. Source: https://sandflysecurity.com/blog/bpfdoor-an-evasive-linux-backdoor-technical-analysis
  • Elastic Security Labs releases BPFDoor scanner and configuration extractor tools, publishes YARA rules including Linux_Trojan_BPFDoor_5 for packet_loop function detection. Source: https://www.elastic.co/security-labs/a-peek-behind-the-bpfdoor
  • BPFDoor Version 2 emerges with major evasion upgrades: SOCK_DGRAM|SOCK_CLOEXEC replaces SOCK_RAW (evades raw socket detection), SSL with embedded certificates replaces RC4, no /dev/shm residency, fixed environment-matched process names, salted MD5 password hashes. Source: https://haxrob.net/bpfdoor-past-and-present-part-2/
  • SK Telecom detects abnormal activity at 11:20 PM local time. Investigators find unusual logs and deleted files on billing/monitoring servers. BPFDoor identified among 12+ malware strains on home subscriber server. 23 million subscribers' USIM data including authentication keys exfiltrated. Source: https://techcrunch.com/2025/05/08/a-timeline-of-south-korean-telco-giant-skts-data-breach/
  • Trend Micro publishes analysis of previously undiscovered BPFDoor controller binary used by Earth Bluecrow. Controller supports TCP/UDP/ICMP magic packet delivery, password authentication, reverse/bind shell selection, configurable magic byte sequences, and encrypted sessions. Targets confirmed in South Korea, Hong Kong, Myanmar, Malaysia, Egypt. Source: https://www.trendmicro.com/en_us/research/25/d/bpfdoor-hidden-controller.html
  • Sandfly Security publishes updated 2026 BPFDoor detection and hunting guide covering both Version 1 and Version 2. New Sandfly 5.5 detections decode open file descriptors to identify SOCK_DGRAM packet sniffers, improved process_running_sniffer_operating_ipv4_traffic module catches Version 2 evasion. Source: https://sandflysecurity.com/blog/bpfdoor-detection-analysis-and-hunting-tactics-on-linux
  • As of 2026-05-29, BPFDoor remains active: Rapid7's March 26 2026 investigation found new stealthier variants (httpShell, icmpShell, HTTPS-embedded magic packets, ICMP relay C2) in live telecom networks. Red Menshen/Earth Bluecrow keeps operating with no takedown; no CVE applies since it is a post-exploitation backdoor, so ACTIVE stands.

Sources cited for BPFDoor — Chinese Nation-State Linux Backdoor Using Berkeley

Detection coverage for TL-2026-0087

As of 2026-02-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0087 across Splunk SPL, Microsoft KQL and Sigma, covering 33 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
33 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats