Earth Bluecrow, also known as Red Menshen, is a Chinese cyber-espionage threat actor associated with the BPFDoor Linux backdoor. First publicly identified as Red Menshen in 2021, the group has targeted telecommunications, financial-services, and retail organizations across Asia and the Middle East, including organizations in South Korea, Hong Kong, Myanmar, Malaysia, and Egypt. Earth Bluecrow is suspected of compromising a South Korean telecommunications company in 2025. The group uses BPFDoor for covert, persistent access to Linux systems. BPFDoor uses kernel-level Berkeley Packet Filter functionality to inspect raw TCP, UDP, and ICMP traffic for authenticated trigger packets rather than exposing a conventional listening port. It can establish reverse shells, redirect inbound connections to a shell, and support pivoting through compromised environments. Documented defense-evasion behavior includes process-name masquerading and suppression of shell-command history. Earth Bluecrow has deployed updated BPFDoor controller functionality in ongoing espionage operations; the initial-access methods in investigated incidents have not been established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
46 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a threat actor associated in the report’s aggregated section with exploitation activity around React2Shell (CVE-2025-55182) and related RSC/Next.js vulnerabilities.
Named in an aggregated list of actors associated with React2Shell (CVE-2025-55182) exploitation activity.
Earth Bluecrow is conducting long-term cyber espionage using BPFDoor backdoor, targeting communication, finance, and retail sectors in Asia and the Middle East.
Conducts long-term cyber-espionage operations using the Linux BPFDoor backdoor. The group targeted telecommunications, finance, and retail organizations, with operations reported in South Korea, Hong Kong, Myanmar, Malaysia, and Egypt during 2024.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.