In order to carry out espionage on government networks, a long-running and ongoing effort linked to a China-nexus threat actor has implanted itself in telecom networks.
Red Menshen, a threat cluster that is also monitored as Earth Bluecrow, DecisiveArchitect, and Red Dev 18, has been linked to the strategic positioning activity, which entails installing and maintaining covert access mechanisms within crucial locations. Since at least 2021, the group has a history of going on strike against telecom companies throughout the Middle East and Asia.
The secret access methods are “some of the stealthiest digital sleeper cells” that have ever been seen in telecom networks, according to Rapid7.
The campaign’s use of cross-platform command frameworks, credential-harvesting tools, kernel-level implants, and passive backdoors allows the threat actor to continuously occupy networks of interest read more about China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy via Telecom Networks.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
