TF-MAL-elf.bpfdoor
📛 Threat Title
Malware family: BPFDoor
Description
ThreatFox malware family `elf.bpfdoor`. Printable name: BPFDoor. Aliases: JustForFun.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.bpfdoor
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.bpfdoor
IOC database
- Type
- domain
- Value
elf.bpfdoor- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.bpfdoor
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.bpfdoor
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
BPFDoor is a Linux based passive long-term backdoor used by China-based threat actors. First seen in 2021, BPFDoor is named after its usage of Berkley Packet Filter (BPF) to execute single task instructions.
-
web:cyberpress.org
The S2W TALON Threat Research and Intelligence Center has confirmed a recent surge in sophisticated BPFDoor malware attacks targeting organizations, with a notable focus on domestic companies and critical infrastructure providers. First identified by PricewaterhouseCoopers (PwC) in 2021, BPFDoor is a backdoor malware engineered for long-term persistence within Linux environments by leveraging ...
-
web:cybersecuritynews.com
Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities.
-
web:iplogger.org
The upgrade of BPFdoor by Red Menshen signifies a continued commitment by state-sponsored actors to develop highly evasive and persistent malware . For global telecommunication providers, the battle against such sophisticated threats is a continuous, high-stakes endeavor, demanding perpetual vigilance, advanced capabilities, and a shift towards ...
-
web:linuxsecurity.com
BPFDoor stands out among traditional malware because its communication channels can easily remain undetected using standard network monitoring tools. Conventional malware typically opens network ports to establish communication with its command and control server.
-
web:sandflysecurity.com
BPFDoor Introduction BPFDoor is a simple but stealthy Linux backdoor linked to Chinese nation state threat actors. While often found targeting telecommunications infrastructure, it is likely used in other critical infrastructure breaches around the world. This document details detection of BPFDoor versions 1 and 2 by Sandfly Security's agentless intrusion detection and incident response ...
-
web:securityarsenal.com
Defend against the BPFdoor Linux backdoor. Learn detection strategies and remediation steps for this stealthy threat targeting telecom networks.
-
web:www.elastic.co
A peek behind the BPFDoor In this research piece, we explore BPFDoor — a backdoor payload specifically crafted for Linux in order to gain re-entry into a previously or actively compromised target environment.
-
web:www.fortinet.com
FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.
-
web:www.rapid7.com
New research from Rapid7 Labs, involving the analysis of nearly 300 samples, has uncovered 7 new BPFDoor variants acting as a silent trapdoor. Activation allows malware to perfectly blend into the target environment, establishing nearly undetectable persistence in global telecom infrastructure. More in a new blog & whitepaper.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.