Threats · 116 days ago
The real risk is not one implant or one intrusion. It is that separate Chinese APT clusters appear to be using the same Linux framework inside telecom networks, which turns cleanup into a hunt for hidden persistence and proxying nodes, not just a single infected host.
Black Lotus Labs and PwC link Showboat, also called kworker, to Calypso and other Chinese activity against telecoms across Central Asia, APAC, and the Middle East. The campaign has been active since at least mid-2022 and pairs the Linux framework with JFMBackdoor on Windows systems.
Showboat can hide processes, persist as a service, and act as a SOCKS5 proxy and port-forwarding pivot. That means a compromised telco server can be used to mask traffic and extend access deeper into the internal network long after the first endpoint is cleaned.
3 sources covering this story
Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor
Showboat targets Linux telecom systems since mid-2022, enabling C2 access, proxying, and file theft across multiple countries.
Chinese APTs Share Linux Backdoor in Central Asia Telco Attacks
"Showboat" doesn't show off, but clearly it doesn't need to, as it's long helped China spy on small market communications providers.
Chinese hackers target telcos with new Linux, Windows malware
A Chinese cyber-espionage campaign has been targeting telecommunications providers with newly discovered Linux and Windows malware dubbed Showboat and JFMBackdoor, respectively.
Part of the PlainSec briefing for 2026-05-22