Cyber Operations — 2026-03-28

China-Linked Red Menshen Upgrades BPFdoor Backdoor to Deepen Persistence in Global Telecom Networks

Cybersecurity researchers from Rapid7 and Trend Micro identified upgraded variants of BPFdoor, a kernel-level Linux implant used by China-nexus threat actor Red Menshen to maintain persistent access inside telecom networks across the Middle East and Asia. The backdoor operates within the OS kernel using Berkeley Packet Filter hooks, making it effectively invisible to standard detection tools. The campaign targets signaling systems, subscriber data, and communications metadata, enabling bulk intelligence collection on persons of interest. Red Menshen has operated since at least 2021 with a consistent focus on telecommunications infrastructure.

Analysis
BPFdoor's kernel-level persistence mechanism makes it effectively invisible to standard endpoint detection; it operates below the layer where most security tools have visibility. The targeting pattern (telecom signaling systems and subscriber metadata across the Middle East and Asia) suggests this is an intelligence collection platform, not a pre-positioning capability for disruption. The upgraded variant surfaced during the U.S.-Iran conflict; Red Menshen may be exploiting the distraction.
2 sources
  1. China Upgrades the Backdoor It Uses to Spy on Telcos Globally - Dark Reading
  2. China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy via Telecom Networks - The Hacker News

View in full brief →

UNCLASSIFIED // OPEN SOURCE