s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

ET-3271

📛 Threat Title

SIG: BPFDoor icmpShell ICMP artifacts from Rapid7 whitepaper

Category: forum-post First seen: Last updated: Source: Emerging Threats Community

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:community.emergingthreats.net

    @bingohotdog I put together a small BPFDoor ICMP lab and wanted to share a few tested rule ideas based on a recent Rapid7 whitepaper (link in rules). I built a minimal PCAP to exercise the icmpShell related behaviors described by Rapid7 and tested the rules separately in Suricata. As part of the normal workflow, I first checked ET Open / free rules before testing the local rules. The three ...

  • web:cyberpress.org

    Recent analysis of nearly 300 malware samples identified two primary new variants: httpShell and icmpShell . These versions demonstrate a significant improvement in the attackers' operational security. Historically, BPFDoor tried to appear fileless by running from temporary memory and deleting itself upon execution.

  • web:cybersecuritynews.com

    Rapid7 analysts identified seven new BPFDoor variants after conducting a months-long investigation that involved analyzing nearly 300 malware samples. Their research uncovered two primary new variants — icmpShell and httpShell — both of which significantly advance the backdoor's ability to stay hidden and operate without detection.

  • web:forums.grc.com

    SIG : BPFDoor icmpShell ICMP artifacts from Rapid7 whitepaper @bingohotdog I put together a small BPFDoor ICMP lab and wanted to share a few tested rule ideas based on a recent Rapid7 whitepaper (link in rules). I built a minimal PCAP to exercise the icmpShell related behaviors described by Rapid7 and tested the rules separately in Suricata.

  • web:gbhackers.com

    Both the httpShell and icmpShell variants also introduce ICMP‑based relay, effectively turning infected hosts into invisible routers. New research from Rapid7 Labs has uncovered undocumented features leading to the discovery of 7 new BPFDoor variants.

  • web:socprime.com

    Rapid7 Labs identified seven new BPFDoor variants abusing kernel-level Berkeley Packet Filters to maintain stealthy backdoor access in telecom environments. The new families, httpShell and icmpShell , use stateless ICMP and HTTP tunneling with "magic" packet formats and concealed IP fields to establish command-and-control with minimal ...

  • web:www.macquariecloudservices.com

    Introduction BPFdoor reminds me of my old project AmOgh(A rootkit simulator) that I published to help security researchers about 3years ago. In principle, these are both very similar to their trigger functions. I found out about BPFDoor from my colleague Branislav. Google led me to an article by Security researcher Kevin Beaumont, who uncovered a new evasive backdoor targeting Linux associated ...

  • web:www.rapid7.com

    New research from Rapid7 Labs, involving the analysis of nearly 300 samples, has uncovered 7 new BPFDoor variants acting as a silent trapdoor. Activation allows malware to perfectly blend into the target environment, establishing nearly undetectable persistence in global telecom infrastructure. More in a new blog & whitepaper .

  • web:www.rapid7.com

    Rapid7 analyzed the recent BPFDoor variant landscape. A closer look unraveled several undocumented features, some of which have remained unknown for at least five years, leading to the discovery of two primary variants: httpShell and icmpShell .

  • web:www.youtube.com

    As part of our research into stealthy BPFDoor variants (read the blog here: https://r-7.co/3OeQuv8), Rapid7 set up a playground lab to test icmpShell . 2 docker containers simulating an nginx edge ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.