Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
T1027: Obfuscated Files Information Implementation details: Stack strings for passwords and paths prevent static extraction.
T1036.004: Masquerading Implementation details: Alters process arguments to mimic benign daemons like qmgr.
T1070.003: Clear History Implementation details: Injects HISTFILE=/dev/null into environment variables.
T1001: Data Obfuscation Implementation details: icmpShell hides its tracking mechanisms directly inside the network layer headers. By truncating the Linux Process ID (PID) and injecting it into the 16-bit ICMP Identifier field, and hardcoding the ICMP Sequence Number to 1234, it obfuscates its session tracking data as standard network metadata.
Most critical of the novel BPFDoor versions are httpShell, which prioritizes C2 concealment within HTTP traffic to allow BPF logic to view for certain magic markers in inner packets, and icmpShell, which creates an interactive shell to impede static firewall rules while also supporting bidirectional ICMP tunnels, RC4 encryption, and UDP/ICMP hole-punching
T1090: Proxy Implementation details: Uses ICMP relay to bounce traffic through internal segments.
icmpShell, which creates an interactive shell to impede static firewall rules while also supporting bidirectional ICMP tunnels, RC4 encryption, and UDP/ICMP hole-punching
Tactic: Persistence T1205: Traffic Signaling Implementation details: Employs magic bytes and flags like 0xFFFFFFFF as wake-up triggers.
icmpShell, which creates an interactive shell to impede static firewall rules while also supporting bidirectional ICMP tunnels, RC4 encryption, and UDP/ICMP hole-punching
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.