Red Menshen is a China-linked, state-sponsored espionage threat actor active since at least 2021 and also tracked as Earth Bluecrow, DecisiveArchitect, and Red Dev 18. The group is primarily associated with long-term cyberespionage and strategic pre-positioning inside telecommunications infrastructure, with additional targeting of government, financial services, logistics, education, retail, defense, and other critical sectors. Activity has been documented across the Middle East, Asia, Africa, and Europe, with repeated victimology involving telecommunications providers and related backbone or core-network environments. The actor is best known for use of BPFDoor, a stealthy Linux backdoor and passive network implant that abuses Berkeley Packet Filter functionality to inspect traffic for crafted trigger packets rather than exposing conventional listening ports or noisy command-and-control channels. Reported BPFDoor tradecraft includes covert bind-shell and reverse-shell access, process masquerading, execution from volatile locations, timestomping, lock or PID files, shell-history suppression, raw-socket packet inspection, and temporary traffic redirection to hidden shells. Newer variants have been reported to conceal triggers inside legitimate HTTPS traffic, use ICMP-based relay or control mechanisms, and in some cases inspect SCTP traffic relevant to telecom signaling environments. Red Menshen has also been linked to BPFDoor controller tooling that can verify infections, trigger implants from inside victim networks, and support lateral movement. Beyond BPFDoor, Red Menshen has been observed using additional post-compromise tooling including TinyShell, China Chopper, CrossC2, Sliver, Metasploit, Mimikatz, keyloggers, brute-force utilities, credential-interception tools, and custom sniffers. Reported intrusion patterns include exploitation of exposed edge infrastructure and VPN or firewall appliances, use of valid privileged credentials, compromise of virtualization and management systems, movement from edge and transport environments into OSS, NMS, EMS, and mobile-core systems, and selective deployment of stealth implants on mission-critical Linux servers and Kubernetes-hosted telecom functions. Multiple reports characterize the activity as low-noise persistence and access enablement rather than smash-and-grab operations, with no confirmed ransomware use and, in some cases, no confirmed data exfiltration despite extensive pre-positioning. Operational indicators cited in attribution include China nexus, infrastructure and proxying patterns involving China, Hong Kong, and compromised routers in Taiwan, as well as working-hour patterns aligned with PRC business hours and holidays. The actor’s victimology and tradecraft are consistent with intelligence collection objectives focused on telecommunications access, government communications, subscriber-related data flows, and long-term operational access to critical network environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
40 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The threat actor then moved laterally to an unpatched VMware ESXi server and exploited CVE-2021–21972 and CVE-2021–21974 to achieve remote code execution on multiple ESXi hosts, where the BPFdoor controller was deployed.
The threat actor then moved laterally to an unpatched VMware ESXi server and exploited CVE-2021–21972 and CVE-2021–21974 to achieve remote code execution on multiple ESXi hosts, where the BPFdoor controller was deployed.
27 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linked to use of BPFDoor in espionage operations targeting telecommunications providers and other critical sectors.
Chinese state-linked espionage group conducting long-term intrusions into telecommunications providers, using BPFdoor and related tooling to maintain persistent access across edge, transport, and mobile core network environments.
Conducting a long-term cyber espionage campaign against telecommunications infrastructure, using stealthy BPFDoor implants and related tooling to maintain persistent covert access and monitor government communications.
Chinese espionage threat actor operating the BPFdoor backdoor against global telecommunications providers, and also observed targeting government, critical infrastructure, and defense networks with highly stealthy persistence and covert communications.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.