Red Menshen, also known as Earth Bluecrow, DecisiveArchitect, and Red Dev 18, is a China-based, state-linked advanced persistent threat group conducting cyberespionage. Active since at least 2021, it primarily targets telecommunications providers, with additional activity against government, logistics, education, financial services, retail, and defense organizations. Its operations span Asia, the Middle East, Africa, and Europe and emphasize maintaining covert, long-term access to critical communications infrastructure. The group's principal implant is BPFDoor, a passive backdoor associated with Linux and Solaris systems. It uses raw packet capture and Berkeley Packet Filter functionality to inspect incoming traffic for specially crafted activation packets, avoiding a conventional listening port or continuous command-and-control beaconing while dormant. Once activated, it provides bind or reverse shells. Its evasion techniques include process masquerading, execution from memory-backed storage, deletion of executable artifacts, timestomping, shell-history suppression, and temporary firewall traffic redirection. Newer variants conceal activation traffic within HTTPS requests delivered through TLS termination infrastructure, support SCTP inspection, and use ICMP-based communication between compromised hosts. Red Menshen obtains access through vulnerable internet-facing services and edge devices or compromised accounts, including privileged VPN credentials. Operators use internal BPFDoor controllers, webshells, and cross-platform frameworks to move from edge and management environments toward transport-network systems and mobile-core infrastructure, including Kubernetes-hosted workloads. Associated tools include ReGeorg, China Chopper, Mangzamel, Metasploit, CrossC2, Sliver, TinyShell, Mimikatz, PrintSpoofer, custom scanners, keyloggers, and brute-force utilities. Credential dumping, privilege escalation, lateral movement, and SCP-based data exfiltration have been observed. Investigated telecommunications intrusions extending into 2026 also demonstrate strategic pre-positioning without confirmed exfiltration in those particular environments. The group conceals operator access through compromised routers and other relay infrastructure; its operational schedules align with Chinese business hours and public holidays.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
42 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The threat actor then moved laterally to an unpatched VMware ESXi server and exploited CVE-2021–21972 and CVE-2021–21974 to achieve remote code execution on multiple ESXi hosts, where the BPFdoor controller was deployed.
The threat actor then moved laterally to an unpatched VMware ESXi server and exploited CVE-2021–21972 and CVE-2021–21974 to achieve remote code execution on multiple ESXi hosts, where the BPFdoor controller was deployed.
37 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with BPFDoor operations targeting telecommunications infrastructure. The reported Linux backdoors use environment-specific process impersonation and passive packet-triggered activation to evade detection. The article does not explicitly attribute the separate AVERAT deployment in Taiwan to Red Menshen.
Linked to BPFDoor activity targeting telecommunications providers since at least 2021. The article describes newer BPFDoor variants targeting South Korean systems, disguising themselves as email-security components and telecom database processes, and adapting their activation traffic to evade detection. It does not explicitly attribute the Taiwanese AVERAT campaign to Red Menshen.
Used passive Linux backdoors, including BPFDoor, within telecommunications-operator networks.
Linked to use of BPFDoor in espionage operations targeting telecommunications providers and other critical sectors.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.