HomeSecurityShowboat: New Linux malware "hits" telecommunications in the Middle East

Showboat: New Linux malware hits telecommunications in the Middle East

Cybersecurity researchers have revealed details of a new Linux malware dubbed Showboat, which has been used in a campaign targeting a telecommunications provider in the Middle East since at least mid-2022.

Showboat

Showboat is a modular post-exploitation framework designed for Linux systems, capable of creating remote shells, transferring files , and acting as a SOCKS5 proxy, according to Lumen Technologies Black Lotus Labs.

It is estimated that the malware has been used by at least one (and possibly more) group linked to China (based on command and control (C2) nodes and IP addresses).

See also: Hackers exploit Butter Network Bridge for mass MAPO creation

One such threat actor is the Calypso (also known as Bronze Medley and Red Lamassu), which has been active since at least September 2016, targeting state institutions in Brazil, India, Kazakhstan, Russia, Thailand, and Turkey. It was first publicly documented by Positive Technologies in October 2019.

Some of the key tools in its arsenal include PlugX and backdoors such as WhiteBird and BYEBY. The latter is part of a larger cluster monitored by ESET under the alias Mikroceen. Mikroceen’s use has been attributed to a group known as SixLittleMonkeys, which in turn shares tactical overlaps with another China-linked group referred to as Webworm.

This places Showboat alongside other common frameworks such as PlugX, ShadowPad, and NosyDoor that have been used by many groups linked to China. This “pooling of resources” reinforces the presence of a digital vendor that state-sponsored attackers from China rely on to provide them with the necessary tools.

Showboat: New Linux malware hits telecoms in the Middle East

Showboat: Attack on a telecommunications provider

The investigation began with an ELF binary uploaded to VirusTotal in May 2025, with the malware scanning platform classifying it as an advanced Linux backdoor with rootkit-like capabilities. Kaspersky is tracking the object as EvaRAT.

See also: Infostealer in Ukraine: 18-year-old stole 28,000 accounts

The malware is designed to communicate with a C2 server, collect system information , and transmit the information back to the server in a PNG field, as an encrypted and Base64-encoded string. It is also equipped to upload and download files to and from the host computer, hide its presence from the process list, and manage C2 servers.

To hide on the host machine, Showboat retrieves a code snippet hosted on Pastebin, created on January 11, 2022. Additionally, the malware can scan for other devices and connect to them via the SOCKS5 proxy server, suggesting that its main purpose is to establish a base on compromised systems.

“This would allow attackers to interact with machines that are not publicly exposed to the internet and are only accessible via the LAN,” Black Lotus Labs said.

Further infrastructure analysis revealed two victims: an Internet Service Provider (ISP) based in Afghanistan and another unknown entity located in Azerbaijan. A secondary C2 cluster using similar X.509 certificates to the primary C2 server has revealed two potential breaches in the U.S. and one in Ukraine.

“While some attackers are increasingly using tools native to the system to evade detection, others are still deploying persistent malware implants,” Black Lotus Labs researcher Danny Adamitis. “The presence of such threats should be considered an early warning sign, indicating the possibility of broader and more serious security issues within affected networks.”

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: GitHub confirms breach of ~3,800 internal repos – What dev teams should do

Showboat: New Linux malware hits telecoms in the Middle East

Modern cyberattacks are becoming more complex

The Showboat case highlights once again the ever-increasing complexity of modern cyberattacks, as well as the strategic importance that telecommunications infrastructures in the field of digital espionage warfare. The use of modular Linux malware with stealth, proxy tunneling and remote access capabilities shows that state-affiliated threat groups are now investing in highly technical tools, capable of remaining invisible for long periods of time within critical networks. The fact that Showboat appears to be exploited by more than one group associated with China further reinforces concerns about the existence of a broader ecosystem of malware “digital suppliers” for cyberespionage operations.

At the same time, the disclosure of potential breaches in countries in the Middle East, Asia, and the West confirms that attacks of this type are no longer limited to individual targets or geographic regions. Experts warn that such implants can act as the first stage for even more serious attacks, such as data theft, lateral movement into internal networks or sabotage operations. In an era where cyber threats are evolving faster than ever, early detection of suspicious activity and strengthening security in Linux servers and telecommunications infrastructure are now considered a critical priority for organizations and governments worldwide.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS