Skip to content

Malware

BPFDoor

aka JustForFun

BPFDoor is a passive backdoor used by a China-based threat actor.

BPFDoor, also known as JustForFun, is a Linux malware family operated by Red Menshen.

Background

BPFDoor is a passive backdoor leveraged by a China-based threat actor. It can communicate with a C2 over several protocols, namely TCP, UDP, and ICMP, giving the operator multiple ways to interact with the implant.


Source: Malpedia (Fraunhofer FKIE).