Red Menshen is a China-linked, state-sponsored advanced persistent threat group focused on long-term espionage and strategic pre-positioning, particularly within telecommunications infrastructure. It is also tracked as Earth Bluecrow, DecisiveArchitect, and Red Dev 18. Active since at least 2021, the group has targeted telecommunications providers across the Middle East, Asia, Africa, and Europe, with additional targeting of government, financial services, logistics, education, retail, defense, and other critical-infrastructure organizations. A central Red Menshen capability is BPFDoor, a Linux and Solaris passive backdoor that abuses Berkeley Packet Filter functionality to inspect inbound traffic for specially crafted trigger packets. BPFDoor can remain dormant without opening an apparent listening port or producing conventional command-and-control beaconing, then provide bind-shell or reverse-shell access after activation. Variants use raw sockets, traffic signaling over TCP, UDP, ICMP, HTTPS, and in some cases SCTP; newer variants conceal triggers in apparently legitimate HTTPS traffic and use ICMP for low-noise inter-host command relaying. The malware employs process masquerading, in-memory or volatile-location execution, deletion of deployed binaries, timestamp manipulation, firewall-rule manipulation, and shell-history suppression to reduce forensic visibility. Red Menshen operators have used compromised edge infrastructure and valid privileged credentials to enter victim networks, then pivot through management, transport, virtualization, and mobile-core environments. Observed post-compromise tooling includes CrossC2, Sliver, TinyShell, China Chopper, Metasploit, credential-harvesting utilities, keyloggers, and brute-force tools. The group has deployed implants on mission-critical systems and Kubernetes-hosted telecommunications functions, and has tailored process masquerading to server hardware, container platforms, and telecom services. Its operational pattern—persistent covert access, credential collection, reconnaissance, and movement toward core telecom systems—supports an espionage and potential future operational-access objective. No confirmed data exfiltration was established for the documented telecom pre-positioning intrusions.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
40 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The threat actor then moved laterally to an unpatched VMware ESXi server and exploited CVE-2021–21972 and CVE-2021–21974 to achieve remote code execution on multiple ESXi hosts, where the BPFdoor controller was deployed.
The threat actor then moved laterally to an unpatched VMware ESXi server and exploited CVE-2021–21972 and CVE-2021–21974 to achieve remote code execution on multiple ESXi hosts, where the BPFdoor controller was deployed.
27 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used passive Linux backdoors, including BPFDoor, within telecommunications-operator networks.
Linked to use of BPFDoor in espionage operations targeting telecommunications providers and other critical sectors.
Chinese state-linked espionage group conducting long-term intrusions into telecommunications providers, using BPFdoor and related tooling to maintain persistent access across edge, transport, and mobile core network environments.
Conducting a long-term cyber espionage campaign against telecommunications infrastructure, using stealthy BPFDoor implants and related tooling to maintain persistent covert access and monitor government communications.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.