Skip to content
Security matters
Security matters
  • APTs
  • Tijdlijn
  • Kill chain
  • Uitgelicht
  • Privacy
Security matters

New BPFDoor Variants Use Stateless C2 and ICMP Relays to Evade Detection

post, april 7, 2026april 10, 2026

A dangerous Linux backdoor called BPFDoor has returned in a more powerful form, with researchers uncovering new variants built to stay invisible inside critical network infrastructure.

Linked to a China-nexus threat actor group known as Red Menshen, these updated versions target Linux servers embedded deep inside global telecom networks.

Unlike earlier strains, the new variants come equipped with techniques that make them far harder to detect and even harder to remove once they are inside a compromised system.

New BPFDoor Variants Use Stateless C2 and ICMP Relays to Evade Detection: New BPFDoor Variants Use Stateless C2 and ICMP Relays to Evade Detection
critical infrastructure cybersecurity malware 2026China

Bericht navigatie

Previous post
Next post

2020 2023 2024 2025 2026 China Iran North Korea Russia ShinyHunters

©2026 Security matters | WordPress Theme by SuperbThemes