Alpha Cyber

Exposing BPFDoor Rootkit Mapping a Hidden Infrastructure Threat

In the ever-evolving threat landscape, few threats demonstrate the stealth and persistence of BPFDoor, a Linux-based rootkit used by advanced threat actors to backdoor systems while remaining virtually invisible to traditional security controls.

Alpha Cyber Research4 min readupdated 1 Apr 2026
BPFDoor Rootkit

In the ever-evolving threat landscape, few threats demonstrate the stealth and persistence of BPFDoor, a Linux-based rootkit used by advanced threat actors to backdoor systems while remaining virtually invisible to traditional security controls. Designed to exploit the Berkeley Packet Filter (BPF), BPFDoor grants attackers covert remote access, bypassing firewalls and evading detection mechanisms with alarming precision.

At Alpha Cyber, we offer a specialized service: Exposing BPFDoor, a targeted infrastructure mapping engagement designed to uncover, analyze, and remove BPFDoor infections across your enterprise.

Service Overview Mapping BPFDoor Infections

Rather than relying solely on signature-based detection, our service builds a complete infrastructure map of the infection, uncovering hidden relationships, compromised assets, and lateral movements. This contextual visibility is essential for exposing deeply embedded threats like BPFDoor, which often persist unnoticed for months.

Exposing BPFDoor Rootkit Mapping a Hidden Infrastructure Threat

BPFDoor Rootkit Graph

In the ever-evolving threat landscape, few threats demonstrate the stealth and persistence of BPFDoor, a Linux-based rootkit used by advanced threat actors to backdoor systems while remaining virtually invisible to traditional security controls. Designed to exploit the Berkeley Packet Filter (BPF), BPFDoor grants attackers covert remote access, bypassing firewalls and evading detection mechanisms with alarming precision.

At Alpha Cyber, we offer a specialized service: Exposing BPFDoor, a targeted infrastructure mapping engagement designed to uncover, analyze, and remove BPFDoor infections across your enterprise.

Service Overview – Mapping BPFDoor Infections

Rather than relying solely on signature-based detection, our service builds a complete infrastructure map of the infection, uncovering hidden relationships, compromised assets, and lateral movements. This contextual visibility is essential for exposing deeply embedded threats like BPFDoor, which often persist unnoticed for months.

Core Service Phases

1. Data Collection & Recon

Passive and active collection of endpoint telemetry, logs, running services, loaded kernel modules, and network metadata.
Memory and packet capture analysis to detect unauthorized use of BPF filters and suspicious listening behaviors.

2. Infrastructure Mapping

Visual mapping of infected hosts, compromised user accounts, malicious binaries, and command-and-control (C2) communication channels.
Correlation of BPFDoor components across the estate to identify the full extent of the breach, including staging servers and lateral move paths.

3. IOC Correlation

All collected data is enriched with known Indicators of Compromise (IOCs), custom heuristics, and behavior-based detections.
Hosts are scored and prioritized based on the presence of high-fidelity BPFDoor traits.

4. Containment Strategy

Isolate compromised hosts based on infection level.
Provide detailed recommendations for blocking, removal, and validation.

5. Remediation & Eradication

Clean removal of BPFDoor malware, rogue processes, and malicious persistence mechanisms.
Post-removal monitoring to ensure integrity and system stability.

6. Final Deliverables

Full attack surface map of the infection path and affected infrastructure.
Tailored IOC blocklist for your detection and response systems.
Actionable remediation playbooks for IR and SOC teams.

Why Infrastructure Mapping Matters

BPFDoor is not a simple drop-and-delete malware. It embeds itself into system processes, uses passive communication channels, and avoids detection by not opening new ports. Mapping the entire attack infrastructure is critical for:

Identifying indirect infection paths that might bypass endpoint detection.
Visualizing persistence across hybrid environments.
Understanding attack timelines and correlating with other APT behaviors.
Ensuring complete removal, not just file-based cleanup.

BPFDoor IOCs to Block and Monitor

The following table lists confirmed IOCs associated with BPFDoor controllers and malware payloads. We encourage SOC teams to integrate these into detection rules, blocklists, and hunting queries across endpoints, SIEMs, and EDR platforms.

IOC Table – Hashes Related to BPFDoor

CategorySHA-1 / SHA-256 Hash
BPFDoor Controller6227cb77cb4ab1d066eebf14e825dbc0a0a7f1e9
64171d46c8290c5cd88e0fbce9e23dcecbe20865
65e4d507b1de3a1e4820e4c81808fdfd7e238e10
9bb8977cd5fc7be484286be8124154ab8a608d96
BPFDoor Malware02aebc3762e766be0ac24ef57a135398344a8f7e
04aa241c574f0a7ec93ba5d27807d8e78467f21e
16f94f0df6003f1566b2108f55e247f60a316185
1db21dbf41de5de3686195b839e74dc56d542974
28765121730d419e8656fb8d618b2068408fe5ae
291af8adf6fa078692d0bf5e0d9d00c376bb3fff
316ac8215095a24429632849407311b18a16e0cf

Note: All values listed are SHA-1 or SHA-256 file hashes observed in active BPFDoor campaigns. Be aware that APT actors may modify or recompile binaries to avoid signature detection. We recommend pairing hash-based detection with behavioral analytics.

Prevention and Monitoring Tips

While BPFDoor is highly evasive, a combination of defensive layers can reduce its effectiveness:

Enforce strict BPF usage policies Block or alert on suspicious BPF filter usage, especially from user-space processes.
Monitor for suspicious passive listeners BPFDoor doesn’t bind to ports like traditional backdoors. Watch for raw socket usage and anomalous packet inspection behavior.
Audit for rogue binaries and kernel modules Many infections are deployed via custom-built loaders that aren’t visible in standard process listings.
Use behavioral EDR detection Look for patterns like hidden file execution, memory-resident processes, or persistent backdoor sockets.
Collect and monitor system-wide packet captures for backdoor traffic matching known BPFDoor behaviors.

Engagement Models Available

Whether you’re in the midst of an incident or conducting proactive threat hunting, we offer:

Rapid Response Engagements – Full mapping and containment in active BPFDoor incidents.
Threat Hunting as a Service – Periodic or on-demand infrastructure scans with custom IOC correlation.
Remediation Support – Removal, revalidation, and hardening services to protect against reinfection.

Ready to Defend Against BPFDoor?

If you suspect BPFDoor or similar rootkit activity in your environment, or if you need to verify your current controls can detect and contain it, contact us for a customized infrastructure map and response plan.

We also offer ready-to-ingest IOC packages (CSV, JSON, STIX) and can help deploy them across your security stack.

Contact us today to start an engagement or request a BPFDoor threat assessment.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]