China Upgrades BPFdoor Backdoor to Deepen Access in Global Telecom Networks

Chinese APT group Red Menshen has quietly upgraded its BPFdoor malware, making it harder than ever to detect inside telecom, government, and critical infrastructure networks worldwide. Here's what security teams need to know.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region3 min read
A telecommunications tower against a sky background, representing global telecom infrastructure targeted by Chinese cyber espionage

A telecommunications tower against a sky background, representing global telecom infrastructure targeted by Chinese cyber espionage

hinese state-linked hackers have upgraded one of the world's most sophisticated cyber espionage tools — and most telecom operators don't even know it exists.

Researchers at Rapid7 have confirmed that Red Menshen, a Chinese advanced persistent threat (APT) group, has significantly enhanced its BPFdoor backdoor malware. Active since at least late 2025, the upgraded variant is now burrowing deeper into telecommunications networks across Asia-Pacific, Europe, the Middle East, and Africa — as well as government, defense, and critical infrastructure networks globally.

What Is BPFdoor?

BPFdoor is a Linux-based backdoor implant that uses the Berkeley Packet Filter (BPF) to silently monitor incoming network traffic while lying completely dormant. It only activates when it receives a specially crafted trigger — making it nearly invisible to traditional security tools.

The malware has now been made significantly stealthier. Rather than scanning all network traffic for its trigger, the upgraded BPFdoor listens exclusively within HTTPS requests — traffic that firewalls cannot reasonably block and that appears entirely normal even when decrypted. Christiaan Beek, VP of Cyber Intelligence at Rapid7, put it plainly: "They are actually weaponizing our firewalls against us."
The malware pinpoints its trigger with surgical precision, checking a specific byte offset — the 26th — within each incoming request. Only if the activation phrase appears at exactly that position does the implant respond.

Covert Command and Control via Ping Traffic

Perhaps the most striking capability of the upgraded BPFdoor is how Red Menshen manages to direct commands to individual infected machines within a compromised network — without raising alarms.

Rather than using conventional command-and-control (C2) infrastructure, which generates detectable traffic, the group routes instructions between infected hosts using Internet Control Message Protocol (ICMP) pings. A specific value embedded in the ping traffic — 0xFFFFFFFF — signals which machine in the chain should execute a given command, allowing the attackers to target any single implant in a multi-host network with precision.

"No matter how many hops there are in a network, they know exactly where their next implant is," Beek explained. "Nobody's tracing how much ping traffic goes beyond the host."

Disguised as Legitimate Infrastructure
Red Menshen also demonstrates unusually deep knowledge of its targets' environments. Knowing that European and Asian telcos commonly run HPE ProLiant servers, and that 5G deployments increasingly rely on Kubernetes, BPFdoor now disguises itself using legitimate process names and service behaviors associated with both platforms — a level of environment-specific mimicry that goes well beyond standard malware evasion.

The group also deploys custom-built tools to intercept credentials and navigate telco infrastructure with speed and familiarity. "They know so much about the inner workings of telco infrastructure," Beek said. "The moment they are inside, they can move really fast."

What Security Teams Should Do

Standard detection tools are largely ineffective against BPFdoor. Rapid7 recommends that operators shift to proactive threat hunting rather than relying on passive monitoring or signature-based defenses.

The starting point, however, is awareness — and that remains a major gap. "When I spoke to different telcos, they were quite unaware of this threat, and also the implications of it," Beek noted.

Security teams in telecom, government, and critical infrastructure sectors should prioritize hunting for BPFdoor indicators of compromise, auditing unusual ICMP traffic patterns, and reviewing process behavior on Linux servers for signs of mimicry.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

Advanced Persistent Threats Telecom Security Nation-State Cyber Espionage