ThreatPaper
Assessed, Not Confirmed

China-linked Red Menshen is behind the BPFDoor telecom campaign

Assessment

SC Media (March 26, 2026) and Cybersecurity Dive (March 27, 2026) reported that a months-long Rapid7 investigation found China-linked actor Red Menshen installing BPFDoor 'sleeper cells' into telecom networks. That attribution is Rapid7's assessment for its earlier (March 2026) BPFDoor investigation — a separate campaign. It does not extend to the October 2, 2026 SMTP/AVERAT report, which Rapid7 left explicitly unattributed and which found no overlap with any named ORB network. Because BPFDoor has been public since 2021 and its source code leaked in 2022, many actors can build on it, so a reader who carries the Red Menshen attribution forward onto this AVERAT campaign would be conflating two distinct pieces of Rapid7 reporting.

Where this claim appeared

SC Media · 2026-03-26

https://www.scworld.com/news/bpfdoor-hides-deep-inside-the-os-kernel-to-target-telecoms-worldwide

What “Assessed, Not Confirmed” means

A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.

4 of 5 · rating scale

Assessed in

AVERAT and BPFDoor: SMTP-cloaked Linux implants mimic South Korean and Taiwanese mail-security appliances

Think this assessment is wrong? Report an error.