BPFDoor
MITRE ATT&CK: S1161 View on attack.mitre.org
Aliases: JustForFun, Backdoor.Linux.BPFDOOR, Backdoor.Solaris.BPFDOOR.ZAJE, BPFDoor
- First seen
- 2021-01-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- linux
- Related IoCs
- 7 (7 malicious)
- Last IoC activity
- 2026-08-04 07:25:20
- Profile updated
- 2026-07-07 12:36:57
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:cn
Context
BPFDoor is a Linux based passive long-term backdoor used by China-based threat actors. First seen in 2021, BPFDoor is named after its usage of Berkley Packet Filter (BPF) to execute single task instructions. BPFDoor supports multiple protocols for communicating with a C2 including TCP, UDP, and ICMP and can start local or reverse shells that bypass firewalls using iptables.
Recent IoC activity
7 malicious indicators in Maltiverse are attributed to BPFDoor (S1161). The 7 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | ed768dd922742a597257ad684820d7562bb6be215710ec614bd041a22f3d6863.bin | 2026-08-04 | 2 |
| file sample | dbus_socket.elf | 2026-07-16 | 1 |
| file sample | 2025-12-13_6e5231ba10d4c2fd53787d2887acbe9d_bpfdoor_helldown.elf | 2026-06-23 | 1 |
| file sample | 3c54d788de1bf6bd2e7bc7af39270540.bin | 2026-04-15 | 1 |
| file sample | 28bfb3f2067c77b83898ef4e41c9fc573e6aaa8581da9b59bddb782205a0b091.elf | 2026-04-06 | 1 |
| file sample | 2025-12-14_3519460043945db8cae025e1d60a0bd5_bpfdoor_helldown.elf | 2026-03-28 | 1 |
| file sample | 82ed617816453eba2d755642e3efebfcbd19705ac626f6bc8ed238f4fc111bb0 | 2026-03-03 | 1 |
Detection coverage
- 6 YARA rules
- 148 Sigma rules
Malware & tools used
- Indicator Removal (attack-pattern)
- Mutual Exclusion (attack-pattern)
- Execution Guardrails (attack-pattern)
- Overwrite Process Arguments (attack-pattern)
- Socket Filters (attack-pattern)
- Ignore Process Interrupts (attack-pattern)
- Break Process Trees (attack-pattern)
- File Deletion (attack-pattern)
- Timestomp (attack-pattern)
- Unix Shell (attack-pattern)
- Disable or Modify System Firewall (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Prevent Command History Logging (attack-pattern)
Detection rules
- SEKOIA_Backdoor_Lin_Bpfdoor (yara-rule)
- SIGNATURE_BASE_MAL_LNX_Redmenshen_Bpfdoor_May23_1 (yara-rule)
- SIGNATURE_BASE_APT_MAL_LNX_Redmenshen_Bpfdoor_Controller_May22_1 (yara-rule)
- SIGNATURE_BASE_APT_MAL_LNX_Redmenshen_Bpfdoor_Controller_May22_2 (yara-rule)
- SIGNATURE_BASE_APT_MAL_LNX_Redmenshen_Bpfdoor_Controller_May22_3 (yara-rule)
- SIGNATURE_BASE_APT_MAL_LNX_Redmenshen_Bpfdoor_Controller_Generic_May22_1 (yara-rule)
Reports & references
- pwc.com — Yir Cyber Threats Report Download (report)
- troopers.de — 7Cv8Pz (report)
- Trend Micro — Bpfdoor Hidden Controller (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Bpfdoor (report)
- elastic.co — A Peek Behind The Bpfdoor (report)
- Trend Micro — Detecting Bpfdoor Backdoor Variants Abusing Bpf Filters (report)
- nikhilh-20.github.io — Cbpf Bpfdoor (report)
- CrowdStrike — How To Hunt For Decisivearchitect And Justforfun Implant (report)
- unfinished.bike — Fun With The New Bpfdoor 2023 (report)
- bleepingcomputer.com — Stealthier Version Of Linux Bpfdoor Malware Spotted In The Wild (report)
- blog.qualys.com — Heres A Simple Script To Detect The Stealthy Nation State Bpfdoor (report)
- rapid7.com — Tr Bpfdoor Telecom Networks Sleeper Cells Threat Research Report (report)
- haxrob.net — Bpfdoor Past And Present Part 2 (report)
- deepinstinct.com — Bpfdoor Malware Evolves Stealthy Sniffing Backdoor Ups Its Game (report)
- Mandiant — Chinese Espionage Tactics (report)
- doublepulsar.com — Bpfdoor An Active Chinese Global Surveillance Tool 54B078F1A896 (report)
- haxrob.net — Bpfdoor Past And Present Part 1 (report)
- lolcads.github.io — Bpf Memory Forensics With Volatility3 (report)
- en.yna.co.kr — Aen20250526002700320 (report)
- sandflysecurity.com — Bpfdoor An Evasive Linux Backdoor Technical Analysis (report)
- twitter.com — 1523266585133457408 (report)
- elastic.github.io — Article (report)
- twitter.com — 1523227511551033349 (report)
- exatrack.com — Tricephalic Hellkeeper (report)
- MITRE ATT&CK — S1161 (report)
External references
- mitre-attack — S1161
- Harries JustForFun 2022
- JustForFun
- Backdoor.Solaris.BPFDOOR.ZAJE
- Backdoor.Linux.BPFDOOR
- Merces BPFDOOR 2023
- Deep Instinct BPFDoor 2023
- Sandfly BPFDoor 2022
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy