BPFDoor gives attackers hidden long-term access in telecom networks

New research from Rapid7 highlights the continued use of BPFDoor, a stealthy backdoor built for long-term persistence in telecommunications networks. Unlike typical malware it operates passively, remaining dormant until triggered by specially crafted network packets. By leveraging Berkeley Packet Filter capabilities, BPFDoor can monitor all incoming traffic without opening listening ports, allowing it to bypass firewalls and evade conventional detection. That makes it well suited to operations where attackers maintain covert access for extended periods, often unnoticed for years.

What this means for your organisation

Detection built on spotting open ports or outbound connections will not find this. It challenges a common assumption at management level that you would notice if someone were inside. For organisations in critical infrastructure, or those dependent on a telecoms provider, the access may also sit further down the chain than your own network. That is a risk to be handled through supplier requirements.

Berigo recommends

  • Supplement port-based detection with traffic pattern analysis on core Linux servers.
  • Require telecoms and other critical suppliers to explain how they hunt for long-term persistence, not just how they handle incidents.
  • Retain network logs long enough that a foothold established years ago can actually be traced.
  • Treat compromise assessment as a recurring exercise rather than something done after an alert.

Source

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch