BPFDoor — an active Chinese global surveillance tool

Kevin Beaumont
DoublePulsar
Published in
3 min readMay 7, 2022

--

Recently, PwC Threat Intelligence documented the existence of BPFDoor, a passive network implant for Linux they attribute to Red Menshen, a Chinese threat actor group.

You can read more in PwC’s great, yearly threat intelligence brief, here.

PwC plan to present their findings in June:

--

--