The real risk is not one implant or one intrusion. It is that separate Chinese APT clusters appear to be using the same Linux framework inside telecom networks, which turns cleanup into a hunt for hidden persistence and proxying nodes, not just a single infected host.
Black Lotus Labs and PwC link Showboat, also called kworker, to Calypso and other Chinese activity against telecoms across Central Asia, APAC, and the Middle East. The campaign has been active since at least mid-2022 and pairs the Linux framework with JFMBackdoor on Windows systems.
Showboat can hide processes, persist as a service, and act as a SOCKS5 proxy and port-forwarding pivot. That means a compromised telco server can be used to mask traffic and extend access deeper into the internal network long after the first endpoint is cleaned.