Red Menshen is a China-linked, likely state-sponsored espionage threat actor active since at least 2021 and also tracked as Earth Bluecrow, DecisiveArchitect, and Red Dev 18. The group is primarily associated with long-term cyberespionage and strategic pre-positioning inside telecommunications infrastructure, with additional targeting reported in government, finance, logistics, education, retail, defense, and other critical sectors. Its operations have focused heavily on telecommunications providers across Asia, the Middle East, Africa, and Europe, where persistent access could enable surveillance of subscriber activity, signaling data, authentication exchanges, and government communications transiting affected networks. A defining element of Red Menshen tradecraft is use of the BPFDoor backdoor family on Linux and Solaris systems. BPFDoor abuses Berkeley Packet Filter functionality to inspect traffic in kernel space and remain dormant until activated by specially crafted packets, allowing it to avoid conventional listening ports and obvious command-and-control patterns. Reported variants support bind shells, reverse shells, covert controller-driven activation, ICMP-based relay mechanisms, SCTP-aware filtering, and trigger concealment within legitimate-looking HTTPS traffic. The malware has also used process masquerading, execution from memory-backed locations, timestomping, and other stealth measures to reduce forensic visibility. Red Menshen has demonstrated deep familiarity with telecom architectures and has operated across edge, transport, and core environments, including OSS, NMS, EMS, virtualization platforms, and Kubernetes-hosted 5G functions. Reported intrusion chains include exploitation of exposed edge infrastructure and VPN-accessible systems, abuse of valid privileged credentials, movement through weakly segmented network layers, and deployment of BPFDoor only at high-value final objectives for durable covert access. Additional tooling associated with the actor includes TinyShell, China Chopper, CrossC2, Sliver, Metasploit, Mimikatz, keyloggers, brute-force utilities, custom sniffers, and credential interception tools. Observed capabilities include stealthy initial access, persistence, credential theft, reconnaissance, lateral movement, post-exploitation, and defense evasion. Multiple investigations characterize the actor’s activity as low-noise, long-duration access intended primarily for espionage rather than immediate disruptive effects. In several documented telecom intrusions, the activity was assessed as pre-positioning for potential future operational use, with no confirmed data exfiltration in the analyzed cases despite extensive access. Victimology, infrastructure patterns, operational timing, and tooling have been cited in support of attribution to a China-nexus espionage cluster.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The threat actor then moved laterally to an unpatched VMware ESXi server and exploited CVE-2021–21972 and CVE-2021–21974 to achieve remote code execution on multiple ESXi hosts, where the BPFdoor controller was deployed.
The threat actor then moved laterally to an unpatched VMware ESXi server and exploited CVE-2021–21972 and CVE-2021–21974 to achieve remote code execution on multiple ESXi hosts, where the BPFdoor controller was deployed.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linked to use of BPFDoor in espionage operations targeting telecommunications providers and other critical sectors.
Chinese state-linked espionage group conducting long-term intrusions into telecommunications providers, using BPFdoor and related tooling to maintain persistent access across edge, transport, and mobile core network environments.
Conducting a long-term cyber espionage campaign against telecommunications infrastructure, using stealthy BPFDoor implants and related tooling to maintain persistent covert access and monitor government communications.
Chinese espionage threat actor operating the BPFdoor backdoor against global telecommunications providers, and also observed targeting government, critical infrastructure, and defense networks with highly stealthy persistence and covert communications.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.