[ RECORD YEAR ]2023

RedEye / ChamelGang Linux eBPF Core Telecom Signaling Rootkit Discovery

Threat intelligence researchers uncovered RedEye / ChamelGang deploying custom eBPF (Extended Berkeley Packet Filter) kernel rootkits directly inside telecom core network servers to intercept subscriber GTP data and signaling stealthily.

THREAT SEVERITY
9.4 / 10
Target TechnologyExtended Berkeley Packet Filter (eBPF), Linux Kernel Rootkits, GTP-U / Diameter Proxies
OSI Network LayerLayer 3/7 / Linux Kernel eBPF & GTP-U Protocol Stack
Threat Actor / AttributionChamelGang / RedEye (Suspected State-Sponsored APT)
Protocol StandardLinux eBPF Architecture / 3GPP TS 29.281 GTP-U Specifications

01Video Presentation & Conference Keynote

02Deep-Dive Technical Analysis

The threat actors achieved root access on Linux-based carrier signaling gateways and injected malicious eBPF bytecode into kernel socket filter hooks (`kprobes` and `tracepoints`). The rootkit parsed user-plane GTP-U (GPRS Tunnelling Protocol) packet streams, filtered traffic for specific subscriber IMSIs/IPs, and covertly cloned the packet payloads to an offshore command-and-control server without modifying kernel files on disk, creating process anomalies, or triggering conventional EDR alerts.

03Vulnerability & Exploit Flow

Exploit Vector

eBPF bytecode injection into kernel socket tracepoints for invisible packet mirroring.

04Recommended Defense & Mitigation Protocol

Operator Hardening Strategy

Disable unprivileged eBPF (`kernel.unprivileged_bpf_disabled=1`), enforce signed eBPF programs, and deploy kernel integrity monitoring tools (Tetragon/BPFdoor detectors).

05Security Impact & Geopolitical Consequence

Represented a generational shift in telecommunications core espionage, moving from user-space web shells to undetectable kernel eBPF packet-filtering implants embedded inside carrier user-plane and control-plane gateways.

06Authoritative Standards & External References

07Related Topic Cluster Records

TelcoSec Global Ecosystem · Academy & Enterprise Audits

Master 5G Core, SS7 Defense & Subsea Cable Auditing

Ready to turn your historical knowledge into certified hands-on expertise? Register free on TelcoSec Academy to access interactive lab challenges, or consult our enterprise team for carrier-grade signaling assessments and portable BTS hardware.

Hands-on SS7, Diameter & 5G SBA Firewall Defense
5G SA Zero Trust Security Architecture & ProLabs
Enterprise Carrier Auditing & Rogue Base Station Interception
Explore SaaS Academy Labs?Enterprise Consultancy (telco-sec.com)?
SaaS Academy free tier · Enterprise audits for operators