Malware · 166 days ago
Rapid7 Labs discovered seven new BPFDoor variants that operate inside the kernel using Berkeley Packet Filters (BPF) to inspect network traffic and activate via tunneled "magic packets" over stateless protocols. These variants, including httpShell and icmpShell, establish near-undetectable persistence in telecom backbone systems by blending into normal traffic and bypassing traditional security stacks.
This kernel-resident approach means standard file, process, and IOC-based detection methods will miss these backdoors. Effective detection requires kernel telemetry, inspection of active BPF programs, and monitoring for unusual stateless packet patterns. Telecom operators and infrastructure defenders must prioritize hunting for these stealthy implants to prevent prolonged undetected access.
1 source covering this story
New Whitepaper: Stealthy BPFDoor Variants are a Needle That Looks Like Hay
New research from Rapid7 Labs, involving the analysis of nearly 300 samples, has uncovered 7 new BPFDoor variants acting as a silent trapdoor.
New Whitepaper: Stealthy BPFDoor Variants are a Needle That Looks Like Hay
New research from Rapid7 Labs, involving the analysis of nearly 300 samples, has uncovered 7 new BPFDoor variants acting as a silent trapdoor.
Part of the PlainSec briefing for 2026-04-02