Detecting BPFDoor Backdoor Variants Abusing BPF Filters

Advanced persistent threat (APT) groups have broadened their focus to include Linux and cloud servers in the past few years. Noticeable examples include ransomware groups targeting VMware ESXi servers, Mirai botnet variants, and groups targeting the cloud with stealers and cryptomining malware. Similarly, APT groups have increased their presence on non-Windows targets.

An example is Sandworm attacking routers shipped with Linux.

Source: Trend Micro