Security researchers detailed BPFDoor, a stealthy Linux backdoor attributed by PwC to the China-linked group Red Menshen, describing its use in long-running intrusions against telecommunications, government, logistics, and education organizations in the Middle East and Asia. The malware is designed for covert re-entry and persistence, using raw sockets and Berkeley Packet Filter (BPF) logic to inspect network traffic for specially crafted magic packets, then launching a reverse shell, bind shell, or pingback without exposing obvious new listening services.
Researchers said BPFDoor can hide behind legitimate network activity by listening on traffic destined for existing services such as 443, allowing operators to execute commands while avoiding conspicuous firewall or port changes. Analysis showed the malware often copies itself into /dev/shm, deletes the original binary, spoofs process names, creates PID files under /var/run, and can temporarily alter iptables to hijack traffic for command and control; historical samples appeared functionally stable over time, with changes largely limited to hardcoded passwords, filenames, and process names. Elastic and other researchers published hunting guidance, YARA signatures, and tooling to help defenders identify infections.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
Analysis of BPFDoor samples linked to a significant telecommunications provider breach in April 2025 showed newer Linux backdoor variants had evolved to evade existing detections. The updated malware used AF_PACKET SOCK_DGRAM sockets instead of visible raw sockets, dropped older /dev/shm fileless execution behavior, and added SSL with embedded self-signed certificates.
Deep Instinct reported a newer BPFDoor variant that replaced older RC4 and bind-shell mechanisms with static-library encryption, reverse-shell communications, and commands supplied by the C2 server. The latest sample had been submitted to VirusTotal in February 2023 and was reportedly undetected by antivirus engines at the time of analysis.
PwC attributed BPFDoor to the China-linked threat group Red Menshen and reported targeting of telecommunications, government, logistics, and education organizations across the Middle East and Asia.
PwC researchers discovered BPFDoor in 2021 and identified it as a stealthy Linux backdoor used for long-term persistence and covert re-entry.
MITRE ATT&CK documented that BPFDoor uses the Linux utimes() function to alter its executable's timestamp, adding a specific defense-evasion and anti-forensics behavior for the malware.
Elastic Security Labs published a detailed analysis of BPFDoor, describing its behavior, historical sample evolution, and stealth mechanisms. Elastic also released detection content including behavioral rules, hunt queries, six YARA signatures, a scanner, and a configuration extractor.
PwC planned to present its BPFDoor findings in June 2022, indicating an upcoming public disclosure of its research on the malware and its attribution.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 41 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
8 references tracked. Mallory keeps watching after this page renders.
sandflysecurity.com
Open sourcehaxrob.net
Open sourcebleepingcomputer.com
Open sourcedeepinstinct.com
Open sourceelastic.co
Open sourcedoublepulsar.com
Open sourceattack.mitre.org
Open sourcepwc.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.