I have a Synology Router. I have the "Threat Prevention" package installed, which most people probably do not install. It warns about various network events that might be suspicious. A new high severity event popped up today.
The description includes:
community.emergingthreats.net
This BDFDoor Malware technique appears to be new on people's radar, and the detection signature appears to be new as well. Obviously there could be false positives on a new malware signature. In any case, it seems pretty suspicious that my router is sending an ICMP packet to some random address in the middle of the night.
So, I have questions:
1. Is my router really compromised? Does it have a backdoor installed from the factory?
2. Steve: Can you provide a discussion of this BPFDoor ICMP malware trick. Sounds interesting.
3. What can I do about this, if anything? (At least it claims to have dropped the offending packet.)
All I've done so far is reboot my router, and run ShieldsUp! again (all stealthy).
Thanks for any comments.
* SRM 1.3.1-9346 Update 13
* RT6600ax
The description includes:
The following links are provided by Threat Prevention about this event:A Network Trojan was detected
Severity: High
Status: Drop
Source IP: (my router external IP)
Destination IP: 71.47.192.1 (some random Comcast IP)
Time: 2026-05-08 03:20:53
Signature Name:
ET MALWARE BPFDoor ICMP Echo Request with X:
(Outbound) |
New Whitepaper: Stealthy BPFDoor Variants are a Needle That Looks Like Hay
New research from Rapid7 Labs, involving the analysis of nearly 300 samples, has uncovered 7 new BPFDoor variants acting as a silent trapdoor. Activation allows malware to perfectly blend into the target environment, establishing nearly undetectable persistence in global telecom infrastructure...
rapid7.com
SIG: BPFDoor icmpShell ICMP artifacts from Rapid7 whitepaper
@bingohotdog I put together a small BPFDoor ICMP lab and wanted to share a few tested rule ideas based on a recent Rapid7 whitepaper (link in rules). I built a minimal PCAP to exercise the icmpShell related behaviors described by Rapid7 and tested the rules separately in Suricata. As part of...
community.emergingthreats.net
This BDFDoor Malware technique appears to be new on people's radar, and the detection signature appears to be new as well. Obviously there could be false positives on a new malware signature. In any case, it seems pretty suspicious that my router is sending an ICMP packet to some random address in the middle of the night.
So, I have questions:
1. Is my router really compromised? Does it have a backdoor installed from the factory?
2. Steve: Can you provide a discussion of this BPFDoor ICMP malware trick. Sounds interesting.
3. What can I do about this, if anything? (At least it claims to have dropped the offending packet.)
All I've done so far is reboot my router, and run ShieldsUp! again (all stealthy).
Thanks for any comments.
* SRM 1.3.1-9346 Update 13
* RT6600ax

