financetom
Technology
financetom
/
Technology
/
Rapid7 Labs Identifies State-Sponsored Sleeper Cells Embedded in Global Telecommunications Networks
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Rapid7 Labs Identifies State-Sponsored Sleeper Cells Embedded in Global Telecommunications Networks
Mar 26, 2026 6:15 AM

BOSTON, March 26, 2026 (GLOBE NEWSWIRE) -- Rapid7 ( RPD ) , a global leader in AI-powered managed cybersecurity operations, released findings from a months-long research investigation from Rapid7 Labs, “Sleeper Cells in the Telecom Backbone,” detailing a sustained espionage campaign conducted by a China-nexus threat actor, Red Menshen, with covert access inside global telecommunications infrastructure.

The research highlights a shift from opportunistic intrusion to deliberate, long-term pre-positioning inside telecommunications networks. These “sleeper cells” are designed to remain undetected while providing persistent visibility into subscriber activity, signaling systems, and sensitive communications—enabling ongoing intelligence collection across environments that support government, commercial, and critical infrastructure operations.

“If you have access to telecommunications infrastructure, you are not just inside one company, you are operating close to the communication layer of entire populations, which makes this type of access highly valuable and elevates detection to a national-level concern,” said Raj Samani, chief scientist at Rapid7 ( RPD ). “The activity we are seeing continues to evolve in ways that improve stealth and persistence, and organizations should treat detection as the start of investigation, not the end of it.”

The research also identifies critical visibility gaps into persistence at the kernel and packet-filtering layers. Without insight into these areas, service masquerading and stealth activation techniques can remain undetected for extended periods. Organizations must have preemptive detection strategies that identify unusual service masquerading and stealth activation mechanisms before they can be leveraged for high-level intelligence collection.

Key findings:

Persistent access in telecommunications infrastructure: Rapid7 Labs identified coordinated activity establishing long-term, dormant footholds within global telecommunications environments.Kernel-level stealth using BPFdoor: The campaign uses a Linux kernel-level backdoor that operates without opening ports or generating typical beaconing activity, limiting visibility for traditional endpoint and network monitoring tools.Weaponization of encrypted traffic: A newly identified variant of the malware now conceals command triggers within legitimate, encrypted HTTPS traffic. By abusing SSL termination points like load balancers and proxies, the actor can bypass modern security controls to activate dormant implants.Access to telecommunications signaling systems: The investigation found targeting of specialized protocols such as SCTP, enabling visibility into subscriber activity, including location tracking and identity-related data across 4G and 5G networks.Service masquerading within telecommunications environments: The malware mimics legitimate infrastructure and management services, including hardware monitoring and container components, to blend into routine operational activity.

“This is not traditional espionage, it is pre-positioning inside the infrastructure that nations depend on,” said Christiaan Beek, vice president of cyber intelligence at Rapid7 ( RPD ). “We are seeing a persistent access model where attackers embed within core communications systems and maintain that access over extended periods.”

Rapid7 ( RPD ) is working with organizations it believes may be impacted and, to support defenders in identifying potential BPFdoor activity, has released a free, open-source scanning script. The scanning script is designed to detect both previously documented BPFDoor variants and newer samples, and is available to assist organizations in proactively identifying potential compromises. Rapid7’s goal is to help defenders rapidly validate exposure and begin incident response investigations where necessary. In addition, Rapid7 ( RPD ) has incorporated these findings across its detection capabilities, including retroactive threat hunting and updated intelligence available to customers through the Rapid7 Intelligence Hub.

On Thursday, March 26 at 12:20 p.m. PT at RSAC 2026 Conference in San Francisco, Christiaan Beek will be presenting the full scope of this research in his session, “Sleeper Cells in the Telecom Backbone.”

On Monday, March 30, Raj Samani and Christiaan Beek will discuss the findings and the impact on global telecommunications in this exclusive webinar.

About Rapid7 ( RPD )

Rapid7, Inc. ( RPD ) is a global leader in AI-powered managed cybersecurity operations, trusted to advance organizations’ cyber resilience. Open and extensible, the Rapid7 Command Platform integrates security data, enriching it with AI, threat intelligence, and 25 years of expertise and innovation to reduce risk and disrupt attackers. As a recognized leader in preemptive managed detection and response (MDR), Rapid7 ( RPD ) unifies exposure and detection to transform the cybersecurity operations of more than 11,500 customers worldwide. For more information, visit our website, check out our blog, or follow us on LinkedIn or X.

Rapid7 Media Relations

Stacey Holleran

Sr. Manager, Global Communications

[email protected]

(857) 216-7804

Rapid7 Investor Contact

Matt Wells

Vice President, Investor Relations

[email protected]

(617) 865-4277

Image: https://www.globenewswire.com/newsroom/ti?nf=OTY3ODkxOCM3NTA0NDQ5IzIwMjgwNDg=

Image: https://ml.globenewswire.com/media/YmIxY2ZjNWItNGFlMS00YTE3LTlhZTEtNTQxOThiM2U2M2YwLTEwNDAwODUtMjAyNi0wMy0yNi1lbg==/tiny/Rapid7.png Image: Primary Logo

Source: Rapid7 ( RPD )

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
DataBank Expands Financing Vehicle to $1.6B to Support the Next Phase of Expansion
DataBank Expands Financing Vehicle to $1.6B to Support the Next Phase of Expansion
Oct 17, 2025
Expansion of the flexible financing vehicle allows company to accelerate construction projects and meet surging demand for data center capacity   DALLAS, Oct. 17, 2025 /PRNewswire/ -- DataBank, a leading provider of enterprise-class edge colocation, interconnection, and managed cloud services, announced today that it has upsized its existing $725 million credit facility to $1.6 billion in order to finance its...
Boost Mobile to Offer the Powerful New iPad Pro with the M5 Chip
Boost Mobile to Offer the Powerful New iPad Pro with the M5 Chip
Oct 17, 2025
The latest iPad Pro is available to pre-order starting Friday, October 17 at BoostMobile.com. Boost Mobile offering $100 off the new iPad Pro with no trade-in required. LITTLETON, Colo., Oct. 17, 2025 /PRNewswire/ -- Boost Mobile will offer the new iPad Pro featuring the incredibly powerful M5 chip. New and current Boost Mobile customers with an active phone plan can add...
Expert Outlook: Roper Technologies Through The Eyes Of 8 Analysts
Expert Outlook: Roper Technologies Through The Eyes Of 8 Analysts
Oct 17, 2025
In the latest quarter, 8 analysts provided ratings for Roper Technologies ( ROP ) , showcasing a mix of bullish and bearish perspectives. The table below offers a condensed view of their recent ratings, showcasing the changing sentiments over the past 30 days and comparing them to the preceding months. Bullish Somewhat Bullish Indifferent Somewhat Bearish Bearish Total Ratings 2...
The Blood Connection to Assume Operations of Sovah Health – Danville Blood Donor Center
The Blood Connection to Assume Operations of Sovah Health – Danville Blood Donor Center
Oct 17, 2025
Expanded Lifesaving Opportunities for Local Donors DANVILLE, Va.--(BUSINESS WIRE)-- The Blood Connection (TBC), an independent, nonprofit community blood center, became the sole supplier of blood products for Sovah Health – Danville on October 1. TBC will also assume operations of the Sovah Health Blood Donor Center, located at 159 Executive Drive, Suite K, establishing its first permanent location in...
Copyright 2023-2026 - www.financetom.com All Rights Reserved