China-Linked Hackers Embed Kernel Implants in Telecom Backbone
Rapid7 reports a China-linked state actor implanted kernel-level code and passive backdoors inside global telecom backbone systems. The access provides long-term, stealthy persistence to conduct espionage against telecommunications providers, government networks, and other critical infrastructure. Observed tools include BPFdoor kernel backdoors, credential harvesters, CrossC2 beacons, SSH brute-forcers, and TinyShell passive backdoors.