China-linked threat actors have installed “sleeper cells” in telecom networks as part of sustained espionage campaigns, according to a new report.
Cybersecurity firm Rapid7’s findings suggest that threat actors are actively exploiting a stealth Linux backdoor to install malware that mimics legitimate infrastructure and management services like container components to blend in with routine operational activity.
Dubbed "BPFdoor," the backdoor operates without opening ports or generating typical beaconing activity, which the cybersecurity firm said allowed the Chinese-linked actors to avoid detection across traditional endpoint and network monitoring tools.
“This is not traditional espionage; it is pre-positioning inside the infrastructure that nations depend on,” Christiaan Beek, Rapid7’s VP of cyber intelligence, explained. “We are seeing a persistent access model where attackers embed within core communications systems and maintain that access over extended periods.”
The actors are believed to have then installed a newly identified variant of the malware capable of concealing commands within legitimate, encrypted HTTPS traffic to further obfuscate its actions.
Rapid7’s investigation found the threat actors directly targeting protocols that would give them visibility into subscriber activity, such as location tracking and identity-related data across 4G and 5G networks. Among those transmission mechanisms abused were stream control transmission protocol (SCTP), which underpins real-time communication between networks; diameter, which provides authentication messaging services for network access and data mobility applications; signaling system No. 7 (SS7), a long-serving signaling protocol that mediated how resources were applied to calls – and a known vulnerability due to its lack of modern encryption and authentication mechanisms.
Explaining how the backdoor works, the report reads: “At the foundation, much of this infrastructure ultimately runs on hardened, but often standard, Linux or BSD-based bare-metal servers, virtualization stacks, and high-performance network appliances.
“When an adversary implants a persistent backdoor at the kernel level within these environments, they are not simply compromising a server, they are positioning themselves adjacent to subscriber data, signaling flows, and the mechanisms that authenticate and route national and international communications.”
Rapid7’s findings come as the infrastructure sector is still feeling the effects of the 2024 Salt Typhoon attacks. The notorious threat actors are believed to have resurfaced earlier this year, targeting congressional staff email accounts.
This latest report suggests that China-linked hackers never actually went way, with their “sleeper cells” instead remaining undetected with persistent visibility into subscriber activity and network signaling systems.
In a bid to quell growing security concerns, the Federal Communications Commission (FCC) introduced a ban on all imports of foreign-produced routers earlier this week, citing national security fears.
“If you have access to telecommunications infrastructure, you are not just inside one company; you are operating close to the communication layer of entire populations, which makes this type of access highly valuable and elevates detection to a national-level concern,” Rapid7 Chief Schientist Raj Samani added. “The activity we are seeing continues to evolve in ways that improve stealth and persistence, and organizations should treat detection as the start of investigation, not the end of it.”
Comments