Threats · 172 days ago
Rapid7 reports a China-linked state actor implanted kernel-level code and passive backdoors inside global telecom backbone systems. The access provides long-term, stealthy persistence to conduct espionage against telecommunications providers, government networks, and other critical infrastructure. Observed tools include BPFdoor kernel backdoors, credential harvesters, CrossC2 beacons, SSH brute-forcers, and TinyShell passive backdoors.
2 sources covering this story
Espionage campaign targets telecom with stealthy Linux-based backdoor
A China-nexus actor has been able to gain long-term access in a bid to gather intel on government agencies and critical infrastructure providers.
Chinese Hackers Caught Deep Within Telecom Backbone Infrastructure
The state-sponsored threat actor deployed kernel implants and passive backdoors enabling long-term, high-level espionage.
Part of the PlainSec briefing for 2026-03-27