Red Menshen is a China-linked, Chinese state-linked advanced persistent threat (APT) group active since at least 2021. It is also tracked as Earth Bluecrow, DecisiveArchitect, and Red Dev 18. Reporting in the provided content attributes the group with high confidence to long-running espionage activity, primarily against telecommunications providers, with additional targeting reported against government, finance, logistics, retail, education, defense, and critical infrastructure organizations. A central tool associated with Red Menshen is BPFDoor, a stealthy Linux backdoor also observed on Solaris. BPFDoor abuses Berkeley Packet Filter functionality to inspect traffic in the kernel and remain dormant until it receives specially crafted trigger packets, allowing it to avoid exposed listening ports and obvious command-and-control traffic. When triggered, it can spawn bind shells or reverse shells. Multiple reports in the content describe Red Menshen evolving BPFDoor over time, including variants that embed triggers in legitimate HTTPS traffic, use ICMP-based control or relay mechanisms, support SCTP-aware filtering, use process masquerading, and employ stealth features such as execution from /dev/shm, process renaming, timestomping, and legitimate-looking lock filenames. The group has been reported targeting telecom networks across the Middle East and Asia, with victims or targeting noted in South Korea, Hong Kong, Myanmar, Malaysia, Egypt, Turkey, and broader Middle East activity, and later expansion into European telecommunications infrastructure. Rapid7 reporting in the content describes Red Menshen conducting long-term strategic pre-positioning inside telecom environments, including movement from edge devices and VPN access into OSS, NMS, EMS, VMware ESXi, Kubernetes-hosted 5G functions, and mobile core environments. The content states there was no confirmed data exfiltration in the analyzed telecom intrusions and assesses the activity as persistent access and pre-positioning for potential future operational use. Additional tooling and tradecraft mentioned in the content include TinyShell, China Chopper, CrossC2, Sliver, Metasploit, Mimikatz, SSH brute-forcers, keyloggers, credential-harvesting utilities, and custom sniffers. Initial access methods described in the content include exploitation of exposed edge infrastructure and use of valid accounts, including VPN, firewall, and virtualization access. The content also notes use of compromised SOHO routers in Taiwan and Hong Kong as proxy infrastructure, and infrastructure hosted in Hong Kong and China.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The threat actor then moved laterally to an unpatched VMware ESXi server and exploited CVE-2021–21972 and CVE-2021–21974 to achieve remote code execution on multiple ESXi hosts, where the BPFdoor controller was deployed.
The threat actor then moved laterally to an unpatched VMware ESXi server and exploited CVE-2021–21972 and CVE-2021–21974 to achieve remote code execution on multiple ESXi hosts, where the BPFdoor controller was deployed.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese state-linked espionage group conducting long-term intrusions into telecommunications providers, using BPFdoor and related tooling to maintain persistent access across edge, transport, and mobile core network environments.
Conducting a long-term cyber espionage campaign against telecommunications infrastructure, using stealthy BPFDoor implants and related tooling to maintain persistent covert access and monitor government communications.
Chinese espionage threat actor operating the BPFdoor backdoor against global telecommunications providers, and also observed targeting government, critical infrastructure, and defense networks with highly stealthy persistence and covert communications.
Conducting long-term stealthy espionage operations in global telecom networks by installing covert Linux backdoors deep in core infrastructure, with campaigns aimed at high-level espionage against government networks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.