China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy via Telecom Networks post, maart 26, 2026maart 27, 2026 A long-term and ongoing campaign attributed to a China-nexus threat actor has embedded itself in telecom networks to conduct espionage against government networks. The strategic positioning activity, which involves implanting and maintaining stealthy access mechanisms within critical environments, has been attributed to Red Menshen, a threat cluster that’s also tracked as Earth Bluecrow, DecisiveArchitect, and Red Dev 18. The group has a track record of striking telecom providers across the Middle East and Asia since at least 2021. China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy via Telecom Networks: China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy via Telecom Networks critical infrastructure malware 2026China