# BPFDoor Linux backdoor (Red Menshen / Earth Bluecrow) targeting telecom infrastructure and network edge devices

> BPFDoor is a stealthy Linux backdoor that uses Berkeley Packet Filters to stay dormant until a magic packet arrives, with no constant beacons or listening ports. It is used against telecom providers and edge systems such as mail security gateways, VPN appliances and firewalls, and newer variants masquerade as regional software such as Korean anti-spam products and HPE ProLiant agents.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3097
- **ID:** TL-2026-3097
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** Red Menshen (China)
- **Detections:** 9 · **IOCs:** 25 (full data via the Threadlinqs MCP server — Purple tier)

## Description

BPFDoor attaches a Berkeley Packet Filter to a raw AF_PACKET socket so the kernel inspects traffic and the implant activates only when a crafted 'magic' packet (TCP, UDP or ICMP) is seen. Because the socket is passive, there is no listening port, no periodic beacon, and the sniffing is not visible to netstat or ss; the magic packet can bypass host firewall filtering. Per Rapid7's Christiaan Beek (Help Net Security, 2026-10-09), operators keep changing how the trigger is hidden: once defenders learn to spot one activation method, the operators move to another. The malware targets appliances that cannot run EDR agents, including mail security gateways, VPN appliances, firewalls and telecom network edge systems, and in telecom networks it provides access to subscriber data, signaling flows, authentication exchanges and communications metadata for long-term collection.

Rapid7 Labs' whitepaper (published 2026-04-02, updated 2026-09-23, roughly 300 samples analysed) documents seven new variants, F through L. Variant F uses a 26-instruction BPF filter, runs from /var/run/user/0, wipes file descriptors and uses new magic bytes (0x3182, 0x2048, 0x1051, 0x1155, 0x3321, 0x5433). Variant G sniffs TCP/UDP/ICMP in multiple threads and spoofs the HPE process name hpasmlited. Variant H beacons actively with a DNS heartbeat and NTP/SSL-themed domains, and masquerades as HPE ProLiant software (cmathreshd with flags '-p 5 -s OK', lock file /var/run/cma.lock). Variant I uses an 11-instruction filter on TCP port 9999 with magic 0xA9F205C3. Variants J, K and L add an ICMP relay (and, for J and K, HTTP tunneling plus the icmpShell/httpShell families). The v2 magic packet carries a 'Hidden IP' field; a value of -1 (255.255.255.255) makes the implant open a reverse shell to the packet's source, so no hardcoded C2 address is needed. In ICMP relay mode the infected host forwards traffic to an internal target taken from that field. icmpShell uses a hardcoded ICMP sequence number 1234, RC4 key 'icmp' and an invalid ICMP code 1 heartbeat. Anti-forensics include timestomping, HISTFILE=/dev/null, stack strings, and unsetenv('LD_PRELOAD') to defeat user-mode hooks.

Trend Micro's controller analysis of BPFDoor (Earth Bluecrow) describes TCP (0x5293), UDP and ICMP (0x7255) activation modes, an MD5-with-fixed-salt password check, reverse-shell and direct-connection modes (iptables REDIRECT into ports 42391-43390, response marker '3458'), and disabling of command logging (HISTFILE and MYSQL_HISTFILE set to /dev/null). Trend lists victims in South Korea, Myanmar and Hong Kong (telecom), Malaysia (retail) and Egypt (finance) during 2024. The Hacker News (October 2026) reports BPFDoor builds against South Korean systems that impersonate the PID file of SpamSniper, a Korean anti-spam product, and rotate through ten Linux daemon names, alongside a related BPF Rekoobe build and the AVERAT implant against ShareTech appliances (dropper ntpdate, payload udevds, C2 over TCP 25 with a 600-699 second beacon).

Attribution: the Help Net Security source gives none. Other public reporting (PwC, Trend Micro, Rapid7) ties BPFDoor to the China-linked group Red Menshen (aka Earth Bluecrow, DecisiveArchitect, Red Dev 18), active against telecoms in Asia and the Middle East since 2021. Attribution confidence is rated MEDIUM here because it relies on secondary vendor reporting. No CVE is cited for BPFDoor itself; Trend lists exploitation of public-facing applications as the initial compromise path. Severity HIGH is an analyst assessment.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059.004 Unix Shell
- T1205.002 Socket Filters
- T1036.004 Masquerade Task or Service
- T1036.005 Match Legitimate Resource Name or Location
- T1070.006 Timestomp
- T1070.003 Clear Command History
- T1014 Rootkit
- T1685 Disable or Modify Tools
- T1095 Non-Application Layer Protocol
- T1071.003 Mail Protocols
- T1071.004 DNS
- T1572 Protocol Tunneling
- T1090.001 Internal Proxy
- T1573.001 Symmetric Cryptography

## Sources

- [What the BPFDoor backdoor tells us about attacks on the network edge](https://www.helpnetsecurity.com/2026/10/09/christiaan-beek-rapid7-bpfdoor-backdoor/)
- [Rapid7: Stealthy BPFDoor variants whitepaper](https://www.rapid7.com/blog/post/tr-new-whitepaper-stealthy-bpfdoor-variants/)
- [Rapid7: Unmasking the new stealthy BPFDoor variants (PDF)](https://www.rapid7.com/cdn/assets/bltd3dbeae8537bb21b/69ce33a499d6c52de57e4a02/unmasking-the-new-stealthy-BPFDoor-variants.pdf)
- [The Hacker News: Linux backdoors impersonate email](https://thehackernews.com/2026/10/linux-backdoors-impersonate-email.html)
- [Trend Micro: BPFDoor hidden controller](https://www.trendmicro.com/en_us/research/25/d/bpfdoor-hidden-controller.html)
- [IMDA advisory: Earth Bluecrow deploys BPFDoor malware across telcos in Asia](https://www.imda.gov.sg/-/media/imda/files/regulations-and-licensing/regulations/advisories/infocomm-media-cyber-security/earth-bluecrow-deploys-bpfdoor-malware-across-telcos-in-asia.pdf)
- [SOC Prime: BPFDoor variants hide in plain sight](https://socprime.com/active-threats/whitepaper-stealthy-bpfdoor/)
- [RH-ISAC: Chinese threat actors implant BPFdoor in telecom networks](https://rhisac.org/threat-intelligence/chinese-threat-actors-implant-bpfdoor-in-telecom-networks/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3097
