logo

分析简版-英文

ID: 35dd51de-df9e-4f93-b95d-600469e55c09

STIX ID: report--35dd51de-df9e-4f93-b95d-600469e55c09

Threat Score

95/100

Uploaded: 2026-08-11

Published Date: 2022-02-22

Last Modified Date: 2022-02-22

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive summary:** Bvp47 is a highly advanced, long-lived Linux backdoor (named from 'Bvp' and 0x47) analyzed by Pangu Lab and linked via leaked Shadow Brokers files (including RSA private keys) to the Equation Group/NSA; it implements a stealthy SYN-knock/BPF kernel-level covert channel, kernel module/rootkit techniques (inline hooks, SELinux bypass, custom LKM loader), multi-slice encrypted payloads, and complex crypto for C2, and was observed in a large, multi-year global campaign affecting hundreds of hosts across dozens of countries.