Minacce · 131 giorni fa
Il vero rischio non è un singolo implant o una singola intrusione. È che cluster APT cinesi separati sembrano usare lo stesso framework Linux all’interno delle reti telecom, trasformando la bonifica in una caccia alla persistenza nascosta e ai nodi di proxying, non solo a un singolo host infetto.
3 fonti che coprono questa storia
Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor
Showboat targets Linux telecom systems since mid-2022, enabling C2 access, proxying, and file theft across multiple countries.
Chinese APTs Share Linux Backdoor in Central Asia Telco Attacks
"Showboat" doesn't show off, but clearly it doesn't need to, as it's long helped China spy on small market communications providers.
Chinese hackers target telcos with new Linux, Windows malware
A Chinese cyber-espionage campaign has been targeting telecommunications providers with newly discovered Linux and Windows malware dubbed Showboat and JFMBackdoor, respectively.
Part of the PlainSec briefing for 2026-05-22