New Whitepaper: Stealthy BPFDoor Variants are a Needle That Looks Like Hay
2026-04-03T07:23:51Z•876d01d1d9cb98fb91a33b0066cb3321656522be15ccf8a5756d0b785aed433d
APTBPFBPFDoorBerkeley Packet FilterCVE-2026-23767ESC/POSEclipse Che RCE','CVSS critique','AI-powered MDR','red teamingIABICMP relayMetasploitRDPRDWebRapid7Red MenshenVPNdetection and responsehttpShellicmpShellinitial access brokerskernel backdoormagic packetnetwork stealthpersistencestateless C2telecom infrastructure
What happened
Rapid7 Labs published a whitepaper identifying seven new BPFDoor variants — a stealthy kernel-level backdoor that leverages Berkeley Packet Filters (BPF) to inspect traffic inside the OS kernel and establish persistence in telecom infrastructure. Two primary variants, “httpShell” and “icmpShell,” use stateless C2 routing, ICMP relay, and a “magic packet” delivered via stateless protocols to create nearly undetectable command-and-control. The research analyzed ~300 samples, attributes activity to a China-nexus actor (Red Menshen), and provides detection/response guidance. The same Rapid7 feed包含
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 876d01d1d9cb98fb91a33b0066cb3321656522be15ccf8a5756d0b785aed433d
- Enrichment time
- 2026-04-03T07:23:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.