Threats · 172 days ago
The implants act as dormant sleeper cells that can monitor signaling and subscriber flows, enabling targeted espionage against government, telecom, and financial networks.
4 sources covering this story
China Upgrades the Backdoor It Uses to Spy on Telcos Globally
Chinese APT Red Menshen's super-advanced BPFdoor malware defeats traditional cybersecurity protections. All telcos can do, really, is try hunting it down.
China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy via Telecom Networks
China-linked Red Menshen embeds BPFDoor in telecom networks since 2021, enabling stealth espionage via kernel implants.
Researchers have released a scanning script to help with detection of hard-to-spot BPFDoor implants used by Salt Typhoon.
BPFdoor in Telecom Networks: Sleeper Cells in the backbone
A months-long investigation by Rapid7 Labs has uncovered evidence of an advanced China-nexus threat actor placing stealthy digital sleeper cells in telecommunications networks, in order to carry out high-level espionage – including against government networks.
Part of the PlainSec briefing for 2026-03-29