Exposing BPFDoor Rootkit Mapping a Hidden Infrastructure Threat
In the ever-evolving threat landscape, few threats demonstrate the stealth and persistence of BPFDoor, a Linux-based rootkit used by advanced threat actors to backdoor systems while remaining virtually invisible to traditional security controls.

In the ever-evolving threat landscape, few threats demonstrate the stealth and persistence of BPFDoor, a Linux-based rootkit used by advanced threat actors to backdoor systems while remaining virtually invisible to traditional security controls. Designed to exploit the Berkeley Packet Filter (BPF), BPFDoor grants attackers covert remote access, bypassing firewalls and evading detection mechanisms with alarming precision.
At Alpha Cyber, we offer a specialized service: Exposing BPFDoor, a targeted infrastructure mapping engagement designed to uncover, analyze, and remove BPFDoor infections across your enterprise.
Service Overview Mapping BPFDoor Infections
Rather than relying solely on signature-based detection, our service builds a complete infrastructure map of the infection, uncovering hidden relationships, compromised assets, and lateral movements. This contextual visibility is essential for exposing deeply embedded threats like BPFDoor, which often persist unnoticed for months.
Exposing BPFDoor Rootkit Mapping a Hidden Infrastructure Threat

In the ever-evolving threat landscape, few threats demonstrate the stealth and persistence of BPFDoor, a Linux-based rootkit used by advanced threat actors to backdoor systems while remaining virtually invisible to traditional security controls. Designed to exploit the Berkeley Packet Filter (BPF), BPFDoor grants attackers covert remote access, bypassing firewalls and evading detection mechanisms with alarming precision.
At Alpha Cyber, we offer a specialized service: Exposing BPFDoor, a targeted infrastructure mapping engagement designed to uncover, analyze, and remove BPFDoor infections across your enterprise.
Service Overview – Mapping BPFDoor Infections
Rather than relying solely on signature-based detection, our service builds a complete infrastructure map of the infection, uncovering hidden relationships, compromised assets, and lateral movements. This contextual visibility is essential for exposing deeply embedded threats like BPFDoor, which often persist unnoticed for months.
Core Service Phases
1. Data Collection & Recon
Passive and active collection of endpoint telemetry, logs, running services, loaded kernel modules, and network metadata.
Memory and packet capture analysis to detect unauthorized use of BPF filters and suspicious listening behaviors.
2. Infrastructure Mapping
Visual mapping of infected hosts, compromised user accounts, malicious binaries, and command-and-control (C2) communication channels.
Correlation of BPFDoor components across the estate to identify the full extent of the breach, including staging servers and lateral move paths.
3. IOC Correlation
All collected data is enriched with known Indicators of Compromise (IOCs), custom heuristics, and behavior-based detections.
Hosts are scored and prioritized based on the presence of high-fidelity BPFDoor traits.
4. Containment Strategy
Isolate compromised hosts based on infection level.
Provide detailed recommendations for blocking, removal, and validation.
5. Remediation & Eradication
Clean removal of BPFDoor malware, rogue processes, and malicious persistence mechanisms.
Post-removal monitoring to ensure integrity and system stability.
6. Final Deliverables
Full attack surface map of the infection path and affected infrastructure.
Tailored IOC blocklist for your detection and response systems.
Actionable remediation playbooks for IR and SOC teams.
Why Infrastructure Mapping Matters
BPFDoor is not a simple drop-and-delete malware. It embeds itself into system processes, uses passive communication channels, and avoids detection by not opening new ports. Mapping the entire attack infrastructure is critical for:
Identifying indirect infection paths that might bypass endpoint detection.
Visualizing persistence across hybrid environments.
Understanding attack timelines and correlating with other APT behaviors.
Ensuring complete removal, not just file-based cleanup.
BPFDoor IOCs to Block and Monitor
The following table lists confirmed IOCs associated with BPFDoor controllers and malware payloads. We encourage SOC teams to integrate these into detection rules, blocklists, and hunting queries across endpoints, SIEMs, and EDR platforms.
IOC Table – Hashes Related to BPFDoor
| Category | SHA-1 / SHA-256 Hash |
|---|---|
| BPFDoor Controller | 6227cb77cb4ab1d066eebf14e825dbc0a0a7f1e9 |
| 64171d46c8290c5cd88e0fbce9e23dcecbe20865 | |
| 65e4d507b1de3a1e4820e4c81808fdfd7e238e10 | |
| 9bb8977cd5fc7be484286be8124154ab8a608d96 | |
| BPFDoor Malware | 02aebc3762e766be0ac24ef57a135398344a8f7e |
| 04aa241c574f0a7ec93ba5d27807d8e78467f21e | |
| 16f94f0df6003f1566b2108f55e247f60a316185 | |
| 1db21dbf41de5de3686195b839e74dc56d542974 | |
| 28765121730d419e8656fb8d618b2068408fe5ae | |
| 291af8adf6fa078692d0bf5e0d9d00c376bb3fff | |
| 316ac8215095a24429632849407311b18a16e0cf |
Note: All values listed are SHA-1 or SHA-256 file hashes observed in active BPFDoor campaigns. Be aware that APT actors may modify or recompile binaries to avoid signature detection. We recommend pairing hash-based detection with behavioral analytics.
Prevention and Monitoring Tips
While BPFDoor is highly evasive, a combination of defensive layers can reduce its effectiveness:
Enforce strict BPF usage policies Block or alert on suspicious BPF filter usage, especially from user-space processes.
Monitor for suspicious passive listeners BPFDoor doesn’t bind to ports like traditional backdoors. Watch for raw socket usage and anomalous packet inspection behavior.
Audit for rogue binaries and kernel modules Many infections are deployed via custom-built loaders that aren’t visible in standard process listings.
Use behavioral EDR detection Look for patterns like hidden file execution, memory-resident processes, or persistent backdoor sockets.
Collect and monitor system-wide packet captures for backdoor traffic matching known BPFDoor behaviors.
Engagement Models Available
Whether you’re in the midst of an incident or conducting proactive threat hunting, we offer:
Rapid Response Engagements – Full mapping and containment in active BPFDoor incidents.
Threat Hunting as a Service – Periodic or on-demand infrastructure scans with custom IOC correlation.
Remediation Support – Removal, revalidation, and hardening services to protect against reinfection.
Ready to Defend Against BPFDoor?
If you suspect BPFDoor or similar rootkit activity in your environment, or if you need to verify your current controls can detect and contain it, contact us for a customized infrastructure map and response plan.
We also offer ready-to-ingest IOC packages (CSV, JSON, STIX) and can help deploy them across your security stack.
Contact us today to start an engagement or request a BPFDoor threat assessment.



