BPFDoor

MITRE ATT&CK: S1161 View on attack.mitre.org

Aliases: JustForFun, Backdoor.Linux.BPFDOOR, Backdoor.Solaris.BPFDOOR.ZAJE, BPFDoor

First seen
2021-01-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
linux
Related IoCs
7 (7 malicious)
Last IoC activity
2026-08-04 07:25:20
Profile updated
2026-07-07 12:36:57

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:cn

Context

BPFDoor is a Linux based passive long-term backdoor used by China-based threat actors. First seen in 2021, BPFDoor is named after its usage of Berkley Packet Filter (BPF) to execute single task instructions. BPFDoor supports multiple protocols for communicating with a C2 including TCP, UDP, and ICMP and can start local or reverse shells that bypass firewalls using iptables.

Recent IoC activity

7 malicious indicators in Maltiverse are attributed to BPFDoor (S1161). The 7 most recently updated:

Detection coverage

  • 6 YARA rules
  • 148 Sigma rules

Malware & tools used

  • Indicator Removal (attack-pattern)
  • Mutual Exclusion (attack-pattern)
  • Execution Guardrails (attack-pattern)
  • Overwrite Process Arguments (attack-pattern)
  • Socket Filters (attack-pattern)
  • Ignore Process Interrupts (attack-pattern)
  • Break Process Trees (attack-pattern)
  • File Deletion (attack-pattern)
  • Timestomp (attack-pattern)
  • Unix Shell (attack-pattern)
  • Disable or Modify System Firewall (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Prevent Command History Logging (attack-pattern)

Detection rules

  • SEKOIA_Backdoor_Lin_Bpfdoor (yara-rule)
  • SIGNATURE_BASE_MAL_LNX_Redmenshen_Bpfdoor_May23_1 (yara-rule)
  • SIGNATURE_BASE_APT_MAL_LNX_Redmenshen_Bpfdoor_Controller_May22_1 (yara-rule)
  • SIGNATURE_BASE_APT_MAL_LNX_Redmenshen_Bpfdoor_Controller_May22_2 (yara-rule)
  • SIGNATURE_BASE_APT_MAL_LNX_Redmenshen_Bpfdoor_Controller_May22_3 (yara-rule)
  • SIGNATURE_BASE_APT_MAL_LNX_Redmenshen_Bpfdoor_Controller_Generic_May22_1 (yara-rule)

Reports & references

  • pwc.com — Yir Cyber Threats Report Download (report)
  • troopers.de — 7Cv8Pz (report)
  • Trend Micro — Bpfdoor Hidden Controller (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Bpfdoor (report)
  • elastic.co — A Peek Behind The Bpfdoor (report)
  • Trend Micro — Detecting Bpfdoor Backdoor Variants Abusing Bpf Filters (report)
  • nikhilh-20.github.io — Cbpf Bpfdoor (report)
  • CrowdStrike — How To Hunt For Decisivearchitect And Justforfun Implant (report)
  • unfinished.bike — Fun With The New Bpfdoor 2023 (report)
  • bleepingcomputer.com — Stealthier Version Of Linux Bpfdoor Malware Spotted In The Wild (report)
  • blog.qualys.com — Heres A Simple Script To Detect The Stealthy Nation State Bpfdoor (report)
  • rapid7.com — Tr Bpfdoor Telecom Networks Sleeper Cells Threat Research Report (report)
  • haxrob.net — Bpfdoor Past And Present Part 2 (report)
  • deepinstinct.com — Bpfdoor Malware Evolves Stealthy Sniffing Backdoor Ups Its Game (report)
  • Mandiant — Chinese Espionage Tactics (report)
  • doublepulsar.com — Bpfdoor An Active Chinese Global Surveillance Tool 54B078F1A896 (report)
  • haxrob.net — Bpfdoor Past And Present Part 1 (report)
  • lolcads.github.io — Bpf Memory Forensics With Volatility3 (report)
  • en.yna.co.kr — Aen20250526002700320 (report)
  • sandflysecurity.com — Bpfdoor An Evasive Linux Backdoor Technical Analysis (report)
  • twitter.com — 1523266585133457408 (report)
  • elastic.github.io — Article (report)
  • twitter.com — 1523227511551033349 (report)
  • exatrack.com — Tricephalic Hellkeeper (report)
  • MITRE ATT&CK — S1161 (report)

External references