Sophos X-Ops reported that attackers used covert communication channels in a backdoor deployed against network-connected devices, allowing malicious traffic to blend into normal activity and making the intrusion harder to detect. The operation involved a backdoor designed to maintain access on compromised devices while concealing command-and-control exchanges from defenders monitoring conventional indicators.
The finding highlights a stealth technique that can complicate incident response on edge infrastructure and other embedded systems, where visibility is often limited. By hiding communications inside seemingly legitimate traffic patterns, the attackers increased the likelihood of long-term persistence and reduced the chance that standard network monitoring would immediately identify the compromise.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
A new report described BPFDoor variants that hide communications through stateless command-and-control methods and ICMP relay techniques. The disclosure added technical detail on how the malware operates and evades detection.
Sophos X-Ops published research describing attackers using covert channels in a backdoor targeting devices. No additional incident dates or intermediate developments are provided in the reference metadata.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.