Rapid7 reported that the China-linked espionage group Red Menshen has expanded a long-running campaign against global telecommunications providers by deploying upgraded BPFDoor implants designed for covert, persistent access inside Linux-based core infrastructure. Victims span the Middle East, Africa, Asia-Pacific, and Europe, with reporting tying activity to telecom environments in South Korea, Hong Kong, Myanmar, Malaysia, Egypt, and other regional networks. The malware abuses Berkeley Packet Filter functionality to inspect traffic from within the kernel and stays dormant until it receives specially crafted trigger packets, allowing it to avoid exposed listening ports and conventional command-and-control patterns. Researchers said the campaign supports strategic surveillance and pre-positioning, potentially exposing telecom signaling and authentication data tied to subscriber identity, mobility, and government communications.
Newly documented BPFDoor variants hide activation inside seemingly legitimate HTTPS traffic, use fixed trigger offsets and magic markers, add ICMP-based relay and shell capabilities, and in some cases beacon outbound over port 443 while masquerading as normal NTP- or management-related traffic. Rapid7 also described variants that monitor telecom-relevant protocols such as SCTP, wipe file descriptors, timestomp artifacts, run from paths such as /var/run/user/0, and disguise themselves as HPE ProLiant or Kubernetes-related processes. Alongside BPFDoor, operators used tools including CrossC2, TinyShell, Sliver, brute-force utilities, and credential theft tooling to move from exposed edge devices into telecom cores. Rapid7 released a detection script for known BPFDoor samples and urged defenders to hunt for structural indicators such as AF_PACKET socket creation, attached BPF filters, spoofed root processes, and anomalous ICMP markers rather than relying on payload inspection alone.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
SC Media reported on a Rapid7 analysis identifying seven new BPFDoor variants that improve stealth and resilience in telecom compromises. The coverage highlighted variants such as httpShell and icmpShell, along with an active-beaconing sample using NTP-themed domains.
Rapid7 published a whitepaper documenting multiple new BPFDoor variants that add stealth, persistence, and command-and-control flexibility, including ICMP shells, HTTP-based control, active beaconing over port 443, and anti-forensics features. The report also described detection opportunities based on structural network and process anomalies rather than payload inspection.
Rapid7 said the China-linked threat cluster Red Menshen has targeted telecommunications providers in the Middle East and Asia since at least 2021, using BPFDoor and other tooling to maintain covert access in telecom environments.
Rapid7 disclosed a months-long Red Menshen espionage campaign targeting telecom providers across Asia, the Middle East, and other regions. The researchers identified a previously undocumented BPFDoor variant that hides triggers inside HTTPS traffic and uses ICMP-based relays for low-noise command routing.
Rapid7 released a scanning script to help defenders detect known BPFDoor variants on Linux systems in critical infrastructure environments. The company warned the tool should complement broader detection efforts because stealthier or evolving samples may evade it.
Rapid7 reported that China-linked actors implanted long-term BPFDoor access in telecom networks to support strategic pre-positioning and surveillance. The report said the malware could hide commands in legitimate HTTPS traffic and inspect telecom signaling and authentication protocols.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcerapid7.com
Open sourcerapid7.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourcesdxcentral.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.