BPFdoor is a stealth Linux backdoor engineered to operate within the operating system kernel, abusing Berkeley Packet Filter (BPF) functionality to inspect network traffic directly inside the kernel.