RedEye / ChamelGang Linux eBPF Core Telecom Signaling Rootkit Discovery
Threat intelligence researchers uncovered RedEye / ChamelGang deploying custom eBPF (Extended Berkeley Packet Filter) kernel rootkits directly inside telecom core network servers to intercept subscriber GTP data and signaling stealthily.
01Video Presentation & Conference Keynote
02Deep-Dive Technical Analysis
The threat actors achieved root access on Linux-based carrier signaling gateways and injected malicious eBPF bytecode into kernel socket filter hooks (`kprobes` and `tracepoints`). The rootkit parsed user-plane GTP-U (GPRS Tunnelling Protocol) packet streams, filtered traffic for specific subscriber IMSIs/IPs, and covertly cloned the packet payloads to an offshore command-and-control server without modifying kernel files on disk, creating process anomalies, or triggering conventional EDR alerts.
03Vulnerability & Exploit Flow
eBPF bytecode injection into kernel socket tracepoints for invisible packet mirroring.
04Recommended Defense & Mitigation Protocol
Disable unprivileged eBPF (`kernel.unprivileged_bpf_disabled=1`), enforce signed eBPF programs, and deploy kernel integrity monitoring tools (Tetragon/BPFdoor detectors).
05Security Impact & Geopolitical Consequence
Represented a generational shift in telecommunications core espionage, moving from user-space web shells to undetectable kernel eBPF packet-filtering implants embedded inside carrier user-plane and control-plane gateways.
06Authoritative Standards & External References
07Related Topic Cluster Records
Master 5G Core, SS7 Defense & Subsea Cable Auditing
Ready to turn your historical knowledge into certified hands-on expertise? Register free on TelcoSec Academy to access interactive lab challenges, or consult our enterprise team for carrier-grade signaling assessments and portable BTS hardware.