
🚨China-Linked Hackers Deploy Stealthy BPFDoor Backdoor to Infiltrate Telecom Networks for Government Espionage
➡️The China-linked threat group Red Menshen is executing a widespread espionage campaign targeting telecom networks and government systems by deploying stealthy kernel-level implants. Central to this operation is BPFDoor, a highly evasive Linux backdoor that infiltrates systems through exposed edge services and remains dormant without maintaining visible listening ports. Instead, it continuously monitors internal network traffic and activates only upon receiving a specific "magic" trigger packet. By camouflaging these activation commands within legitimate HTTPS traffic and utilizing ICMP for covert communication between compromised hosts, the attackers achieve long-term persistence and effectively embed hidden digital sleeper cells deep within the telecom backbone to seamlessly evade detection.
Source: The Hacker News (thehackernews.com/2026/03/china-…)
English















