Kernel-Level BPFDoor Variants Evade Detection in Telecom Infrastructure

Rapid7 Labs discovered seven new BPFDoor variants that operate inside the kernel using Berkeley Packet Filters (BPF) to inspect network traffic and activate via tunneled "magic packets" over stateless protocols. These variants, including httpShell and icmpShell, establish near-undetectable persistence in telecom backbone systems by blending into normal traffic and bypassing traditional security stacks. This kernel-resident approach means standard file, process, and IOC-based detection methods will miss these backdoors. Effective detection requires kernel telemetry, inspection of active BPF programs, and monitoring for unusual stateless packet patterns. Telecom operators and infrastructure defenders must prioritize hunting for these stealthy implants to prevent prolonged undetected access.

Part of the PlainSec briefing for 2026-04-02

Sources