By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: New BPFDoor Controller Enables Stealthy al Movement in Linux Server Attacks
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > New BPFDoor Controller Enables Stealthy al Movement in Linux Server Attacks
Computing

New BPFDoor Controller Enables Stealthy al Movement in Linux Server Attacks

News Room
Last updated: 2025/04/16 at 7:03 AM
News Room Published 16 April 2025
Share
SHARE

Apr 16, 2025Ravie LakshmananCyber Espionage / Network Security

Cybersecurity researchers have unearthed a new controller component associated with a known backdoor called BPFDoor as part of cyber attacks targeting telecommunications, finance, and retail sectors in South Korea, Hong Kong, Myanmar, Malaysia, and Egypt in 2024.

“The controller could open a reverse shell,” Trend Micro researcher Fernando Mercês said in a technical report published earlier in the week. “This could allow lateral movement, enabling attackers to enter deeper into compromised networks, allowing them to control more systems or gain access to sensitive data.

The campaign has been attributed to a threat group it tracks as Earth Bluecrow, which is also known as DecisiveArchitect, Red Dev 18, and Red Menshen.

Cybersecurity

BPFDoor is a Linux backdoor that first came to light in 2022, with the malware positioned as a long-term espionage tool for use in attacks targeting entities in Asia and the Middle East at least a year prior to public disclosure.

The most distinctive aspect of the malware is that it creates a persistent-yet-covert channel for threat actors to control compromised workstations and access sensitive data over extended periods of time.

The malware gets its name from the use of Berkeley Packet Filter (BPF), a technology that allows programs to attach network filters to an open socket in order to inspect incoming network packets and monitor for a specific Magic Byte sequence so as to spring into action.

“Because of how BPF is implemented in the targeted operating system, the magic packet triggers the backdoor despite being blocked by a firewall,” Mercês said. “As the packet reaches the kernel’s BPF engine, it activates the resident backdoor. While these features are common in rootkits, they are not typically found in backdoors.”

The latest analysis from Trend Micro has found that the targeted Linux servers have also been infected by a previously undocumented malware controller that’s used to access other affected hosts in the same network after lateral movement.

“Before sending one of the ‘magic packets’ checked by the BPF filter inserted by BPFDoor malware, the controller asks its user for a password that will also be checked on the BPFDoor side,” Mercês explained.

In the next step, the controller directs the compromised machine to perform one of the below actions based on the password provided and the command-line options used –

  • Open a reverse shell
  • Redirect new connections to a shell on a specific port, or
  • Confirm the backdoor is active
Cybersecurity

It’s worth pointing out that the password sent by the controller must match one of the hard-coded values in the BPFDoor sample. The controller, besides supporting TCP, UDP, and ICMP protocols to commandeer the infected hosts, can also enable an optional encrypted mode for secure communication.

Furthermore, the controller supports what’s called a direct mode that enables the attackers to directly connect to an infected machine and obtain a shell for remote access – but only when provided the right password.

“BPF opens a new window of unexplored possibilities for malware authors to exploit,” Mercês said. “As threat researchers, it is a must to be equipped for future developments by analyzing BPF code, which will help protect organizations against BPF-powered threats.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Checkout.com lands major payments deal with eBay – UKTN
Next Article Hammerspace, an unstructured data wrangler used by Nvidia, Meta and Tesla, raises $100M at $500M+ valuation | News
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Chinese EV makers “very welcome” to open plants in France, says minister · TechNode
Computing
Sony’s new flagship headphones automatically use your Pixel’s Bluetooth LE Audio
News
Kuo: No major AirPods hardware updates until AirPods Pro 3 in 2026 – 9to5Mac
News
Putin dealt blow in ‘Super Sunday’ of votes after shock result in election
News

You Might also Like

Computing

Chinese EV makers “very welcome” to open plants in France, says minister · TechNode

2 Min Read
Computing

Taobao drops presale strategy for 618 festival amid “user first” prioritization · TechNode

3 Min Read
Computing

Top 10 SlidesAI Alternatives for Smarter Presentations in 2025

36 Min Read
Computing

Germany bans Lenovo’s products over patent infringement · TechNode

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?