Netskope Threat Labs

BPFDoor

ATP Sandbox Adv. HeuristicsAV

BPFDoor is a Linux backdoor that uses Berkeley Packet Filter rules to sniff network traffic on compromised systems and remain invisible to connection based monitoring. It can activate when it sees a specific packet, open a shell for its operators, and sustain stealthy command and control communication on networks that researchers have linked to Chinese state sponsored actors. Its passive design lets it sit quietly on internet facing servers for long periods before its operators need it.

First seen
May 2022
Last seen
October 2026
BPFdoorBpfDoorBpfdoor

13 techniques across 3 tactics.

TA0002 Execution

TA0005 Stealth

TA0112 Defense Impairment

  • T1686Disable or Modify System Firewall
  • T1690Prevent Command History Logging
Alert Name
Gen:Variant.Linux.BPFDoor.2
Linux.Backdoor.Bpfdoor
Linux.Backdoor.BpfDoor
Linux.Backdoor.BPFDoor
Linux.Trojan.BpfDoor
Linux.Trojan.BPFdoor
Linux.Trojan.BPFDoor
Trojan.Linux.BpfDoor.15
Trojan.Linux.BpfDoor.17
Trojan.Linux.BpfDoor.18