分析简版-英文
ID: 35dd51de-df9e-4f93-b95d-600469e55c09
STIX ID: report--35dd51de-df9e-4f93-b95d-600469e55c09
Threat Score
95/100
Uploaded: 2026-08-11
Published Date: 2022-02-22
Last Modified Date: 2022-02-22
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive summary:** Bvp47 is a highly advanced, long-lived Linux backdoor (named from 'Bvp' and 0x47) analyzed by Pangu Lab and linked via leaked Shadow Brokers files (including RSA private keys) to the Equation Group/NSA; it implements a stealthy SYN-knock/BPF kernel-level covert channel, kernel module/rootkit techniques (inline hooks, SELinux bypass, custom LKM loader), multi-slice encrypted payloads, and complex crypto for C2, and was observed in a large, multi-year global campaign affecting hundreds of hosts across dozens of countries.
