Analysis of the Linux backdoor BPFDoor shows the malware copying itself to /dev/shm/kdmtmpflush, changing the file’s permissions, and then re-launching the new instance through execve with the --init flag to complete setup. During execution it checks for /var/run/haldrund.pid to avoid multiple starts, deletes any prior copy of the payload, and timestomps the replacement file to 2008-10-30 19:17:16 UTC to reduce suspicion. Runtime tracing also showed the malware adopting deceptive process names including dbus-daemon --system and /usr/libexec/postfix/master to blend into normal Linux activity.
The traced sample then created a raw packet socket and attached a BPF filter with SO_ATTACH_FILTER, enabling BPFDoor to watch for specially crafted network traffic used to activate the implant. The backdoor was reported to respond to magic packets containing hardcoded passwords such as justforfun or socket, after which it could send a ping, spawn a reverse shell, or open a bind shell. The behavior highlights a stealth-focused Linux implant that combines fileless-style staging in shared memory, process masquerading, and packet-triggered remote access.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
The analyzed BPFDoor sample sets the timestamps on /dev/shm/kdmtmpflush via utimes to 2008-10-30 19:17:16 UTC as part of its execution flow. This is presented in the tracing analysis as an anti-forensics step after copying and re-executing itself.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.