Cyber & Technology — 2026-04-03

China-Linked APT Red Menshen Embeds Kernel-Level Implants in Telecom Networks Across Three Continents

CYFIRMA's April 3 weekly intelligence report flags Red Menshen (Earth Bluecrow), a China-linked APT embedding kernel-level BPFdoor implants in telecommunications infrastructure across Asia, the Middle East, and the US for sustained espionage. The group exploits legitimate Berkeley Packet Filter functionality, making detection exceptionally difficult. The same report identifies new ransomware threats: Vect (Windows/Linux/ESXi) and Efimer clipper malware targeting cryptocurrency wallets via compromised WordPress sites.

Analysis
BPFdoor variants operating at the kernel level are exceptionally difficult to detect because they exploit legitimate Berkeley Packet Filter functionality built into Linux. Targeting telecommunications infrastructure across three continents suggests an intelligence collection posture rather than pre-positioning for disruption, though the same access enables both. The Iran war has likely increased collection urgency against US military communications transiting commercial telecom networks.
1 sources
  1. Weekly Intelligence Report - 03 April 2026 - CYFIRMA

View in full brief →

UNCLASSIFIED // OPEN SOURCE