BPFDoor is a passive backdoor primarily targeting Linux servers and network-edge appliances, designed to provide covert, long-term access to compromised environments. It attaches classic Berkeley Packet Filter (BPF) programs to packet sockets and inspects incoming traffic for specially formatted activation packets. Before activation, it requires neither continuous beaconing nor a conventional listening port. Its packet inspection can detect activation traffic before local firewall filtering, allowing operators to reach the implant even when the triggering traffic would otherwise be blocked.
Authenticated activation enables remote command execution through reverse or bind shells. Depending on the variant, BPFDoor supports TCP, UDP, and ICMP triggers, encrypted shell communications, file uploads and downloads, and backdoor-liveness checks. Bind-shell implementations temporarily modify firewall redirection rules to route attacker traffic from legitimate service ports to a hidden shell, then remove those rules after connection establishment. Evasion techniques include process masquerading, executable deletion after launch, timestamp manipulation, environment clearing, string obfuscation, and command-history suppression. These behaviors vary across versions; newer variants can retain their on-disk executables and use packet sockets presented as datagram sockets. Reboot persistence can be supplied by external startup mechanisms, including modified initialization scripts. Some controllers encapsulate activation commands in HTTPS POST requests to traverse edge proxies and SSL-offloading infrastructure.
BPFDoor is associated with the China-linked threat actor Red Menshen, also tracked as Earth Bluecrow and DecisiveArchitect. It has been used extensively against telecommunications infrastructure, with additional targeting of financial services, retail, government, education, and logistics organizations. Activity spans Asia, the Middle East, Africa, and the United States. Recent variants imitate regional email-security products such as SpamSniper and services associated with Oracle-based telecommunications platforms. BPFDoor is generally deployed after compromise; no consistent initial infection vector is established. Public availability of its source code complicates attribution of individual deployments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
For example, there's a BPFDoor sample compiled for Solaris that exploits CVE-2019-3010, and there are efforts to bring eBPF to Windows. | The stealthy rootkit-like malware known as BPFDoor (detected as Backdoor.Linux.BPFDOOR) is a backdoor with strong stealth capabilities, most of them related to its use of Berkeley Packet Filtering (BPF).
The threat actor then moved laterally to an unpatched VMware ESXi server and exploited CVE-2021–21972 and CVE-2021–21974 to achieve remote code execution on multiple ESXi hosts, where the BPFdoor controller was deployed. | Rapid7 Labs published the results of a months-long investigation into a sophisticated espionage campaign targeting telecommunications providers worldwide. Their analysis, “BPFdoor in Telecom Networks: Sleeper Cells in the Backbone,” is an excellent technical deep-dive into the BPFdoor malware and its capabilities.
The threat actor then moved laterally to an unpatched VMware ESXi server and exploited CVE-2021–21972 and CVE-2021–21974 to achieve remote code execution on multiple ESXi hosts, where the BPFdoor controller was deployed. | Rapid7 Labs published the results of a months-long investigation into a sophisticated espionage campaign targeting telecommunications providers worldwide. Their analysis, “BPFdoor in Telecom Networks: Sleeper Cells in the Backbone,” is an excellent technical deep-dive into the BPFdoor malware and its capabilities.
"A critical remote code execution (RCE) vulnerability, identified as CVE-2025-55182 and dubbed React2Shell, exists within the React Server Components (RSC) architecture, allowing unauthenticated attackers to execute arbitrary code..."
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BPFDoor opens a SOCK_RAW or AF_PACKET socket and attaches a BPF filter. This looks for marked traffic.
BPFDoor opens a SOCK_RAW or AF_PACKET socket and attaches a BPF filter. This looks for marked traffic.
The stealthy rootkit-like malware known as BPFDoor (detected as Backdoor.Linux.BPFDOOR) is a backdoor with strong stealth capabilities, most of them related to its use of Berkeley Packet Filtering (BPF).
Dubbed "BPFdoor," the backdoor operates without opening ports or generating typical beaconing activity, which the cybersecurity firm said allowed the Chinese-linked actors to avoid detection across traditional endpoint and network monitoring tools.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Based on the password or existence of a password sent in the “magic packet” the backdoor provides a reverse shell, establishes a bind shell, or sends back a ping.
Strings are hidden with a rotating substitution alphabet.
The common thread is regionalized disguise: each sample is aware of the vendor’s software running on the targeted systems and implements process spoofing accordingly.
The SpamSniper /var/run/spamsniper.pid mutex, together with the sample provenance, ties this build to the South Korean cluster.
“Environment variables MYSQL_HISTFILE=/dev/null and HISTFILE=/dev/null are set to suppress shell command logging.”
VIMINIT="set viminfo=", HISTFILE=/dev/null, HISTSIZE=0, and HISTFILESIZE=0.
That key seeds RC4's key-scheduling algorithm, and the resulting S-box is used directly as a keystream.
BPFDoor and Rekoobe samples wait for a magic packet before opening interactive access.
The BPFDoor variants create a raw PF_PACKET socket, attaching a classic BPF filter.
The install branch fires only when /tmp/flag already exists on the filesystem and the .php script does not.
“C2 communication established over raw TCP, UDP, or ICMP packets, using ‘magic bytes’ to maintain stealth and evade traditional application-layer inspection.”
BPFDoor and Rekoobe samples wait for a magic packet before opening interactive access.
158 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
80 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A stealthy Linux backdoor that waits for a special activation packet rather than continuously beaconing or exposing an obvious listening port. The article describes its use for long-term access to telecom environments, including poorly monitored edge appliances such as mail gateways. New versions can masquerade as regional software, including a Korean anti-spam product. Suggested detection checks include processes with deleted executables, unexpected raw packet sockets, and outbound port 25 traffic from non-mail services. Compromise of telecom infrastructure could enable intelligence collection, subscriber tracking, and monitoring of sensitive communications.
Linux backdoor that uses Berkeley Packet Filter to inspect incoming traffic and activate upon receiving a magic packet. The reported variants impersonate SpamSniper components and Oracle-style processes. Operators can deliver activation packets inside HTTPS POST requests through proxies using SSL offloading. Once activated, the backdoor supports TinyShell sessions and file transfers; the report describes integration of TinyShell and Rekoobe logic for data extraction.
Linux backdoor that uses Berkeley Packet Filter functionality to inspect incoming traffic and activate upon receiving a magic packet. Newly observed variants impersonate email-security components and Oracle-style processes. Operators wrap trigger packets in HTTPS POST requests to exploit SSL offloading and potentially evade inspection. Once activated, a sample launches TinyShell for interactive shell access and file transfers; the framework also incorporates Rekoobe logic to support exfiltration.
Linux backdoor observed targeting South Korean systems. The reported variant disguises its processes as SpamSniper components; another sample impersonates processes on Oracle-based telecom subscriber platforms. A BPFDoor controller encapsulates activation triggers in HTTPS POST requests, potentially allowing them to traverse edge proxies and evade conventional deep-packet inspection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.