{"id":950,"date":"2026-03-26T18:43:00","date_gmt":"2026-03-26T16:43:00","guid":{"rendered":"https:\/\/familiebuckens.nl\/?p=950"},"modified":"2026-03-27T18:43:30","modified_gmt":"2026-03-27T16:43:30","slug":"china-linked-red-menshen-uses-stealthy-bpfdoor-implants-to-spy-via-telecom-networks","status":"publish","type":"post","link":"https:\/\/familiebuckens.nl\/index.php\/2026\/03\/26\/china-linked-red-menshen-uses-stealthy-bpfdoor-implants-to-spy-via-telecom-networks\/","title":{"rendered":"China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy via Telecom Networks"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A long-term and ongoing campaign attributed to a China-nexus threat actor has embedded itself in telecom networks to conduct espionage against government networks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The strategic positioning activity, which involves implanting and maintaining stealthy access mechanisms within critical environments, has been attributed to&nbsp;<strong><a href=\"https:\/\/thehackernews.com\/2025\/04\/new-bpfdoor-controller-enables-stealthy.html\" rel=\"noreferrer noopener\" target=\"_blank\">Red Menshen<\/a><\/strong>, a threat cluster that&#8217;s also tracked as Earth Bluecrow, DecisiveArchitect, and Red Dev 18. The group has a track record of striking telecom providers across the Middle East and Asia since at least 2021.<\/p>\n\n\n<a class=\"wp-block-read-more\" href=\"https:\/\/familiebuckens.nl\/index.php\/2026\/03\/26\/china-linked-red-menshen-uses-stealthy-bpfdoor-implants-to-spy-via-telecom-networks\/\" target=\"_self\"><a href=\"https:\/\/thehackernews.com\/2026\/03\/china-linked-red-menshen-uses-stealthy.html?m=1\">China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy via Telecom Networks<\/a><span class=\"screen-reader-text\">: China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy via Telecom Networks<\/span><\/a>","protected":false},"excerpt":{"rendered":"<p>A long-term and ongoing campaign attributed to a China-nexus threat actor has embedded itself in telecom networks to conduct espionage against government networks. The strategic positioning activity, which involves implanting and maintaining stealthy access mechanisms within critical environments, has been attributed to&nbsp;Red Menshen, a threat cluster that&#8217;s also tracked as&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[41,3],"tags":[72,13],"class_list":["post-950","post","type-post","status-publish","format-standard","hentry","category-critical-infrastructure","category-malware","tag-72","tag-china"],"_links":{"self":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/950","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/comments?post=950"}],"version-history":[{"count":1,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/950\/revisions"}],"predecessor-version":[{"id":951,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/950\/revisions\/951"}],"wp:attachment":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/media?parent=950"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/categories?post=950"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/tags?post=950"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}