Showboat is a modular Linux post-exploitation framework and backdoor used in a long-running cyber-espionage campaign active since at least mid-2022. It has been primarily observed targeting telecommunications providers and related critical communications infrastructure in the Middle East, with additional victim or infrastructure links reported in Afghanistan, Azerbaijan, the United States, eastern Europe, and the Donbas region. Multiple sources assess the activity as China-linked or PRC-aligned with moderate confidence, citing command-and-control infrastructure correlations to Chengdu, China, similarities to known Chinese APT tradecraft, and reporting that the malware has been used by the Calypso/Red Lamassu threat group. Kaspersky is also reported to track the malware as EvaRAT.
Showboat is designed for Linux systems, including AMD x86-64, and is intended to provide covert, long-term access after initial compromise. Reported capabilities include spawning a remote shell, uploading and downloading files, changing directories, establishing persistence as a service, functioning as a SOCKS5 proxy, port forwarding or port mapping, swapping command-and-control nodes, and scanning or reaching internal devices accessible only from the compromised host’s LAN. Its role is described as maintaining a foothold and enabling lateral movement deeper into telecom environments.
The malware retrieves an XOR-encrypted configuration using the hardcoded key "look me, AV!". Decrypted configuration data reportedly contains the server address, port settings, and randomized sleep intervals used to vary beacon timing. After execution, Showboat gathers host information including hostname, operating system details, running processes, its own process information, and a desktop screenshot. It packages this data into an encrypted, base64-encoded string and exfiltrates it in a PNG field. One report states it creates a JSON structure containing host information, malware version, and a UUID, then encrypts it using the last five digits of the UUID as the key.
A notable stealth feature is its process-hiding capability. The "hide" command retrieves C source code from external sites such as Pastebin or online forums, compiles it on the victim machine, and abuses /etc/ld.so.preload to hook Linux system calls so its processes are hidden from standard tools such as ps and top. Reported associated filenames include ukpkmkk.c and ukpkmkk.so, and hardcoded process filter names include "kworkers," "dbus," and "autoupdate." The malware also reportedly hides its execution path from local administrators. Researchers reported that a sample uploaded to VirusTotal on May 5, 2025 had zero detections and remained undetected by antivirus products until April 2026.
Reported infrastructure and indicators include the domain telecom.webredirect[.]org, resolving to 139.84.227[.]139, identified as a primary command-and-control server; 194.135.25[.]132 as a related C2; and additional domains such as singtelcom[.]site and kaztelecom[.]shop used to impersonate telecommunications organizations. Other reported infrastructure includes 116.169.244[.]208:2096, geolocated near Chengdu, China, as possible upstream or developer-associated infrastructure. The path /etc/ld.so.preload is specifically identified as an abused persistence and concealment mechanism.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Linux implant Calypso uses in these attacks, dubbed Showboat/kworker, is a modular post-exploitation framework built for long-term persistence after initial compromise.
The Linux implant Calypso uses in these attacks, dubbed Showboat/kworker, is a modular post-exploitation framework built for long-term persistence after initial compromise.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Our analysis revealed several pre-built functions that an operator could call. These functions allow the operators to upload and download files to and from the host machine, hide the agent itself from the process list, obtain persistence as a service, and swap out C2 nodes.
Our analysis revealed several pre-built functions that an operator could call. These functions allow the operators to upload and download files to and from the host machine, hide the agent itself from the process list, obtain persistence as a service, and swap out C2 nodes.
When triggered, it fetches a small C source file from a Pastebin page set up by the attackers, compiles it on the victim’s machine, and uses a Linux feature called ld.so.preload to hook system calls. This makes the malware’s own processes completely invisible to standard tools like ps and top.
“The file was XOR-encrypted with a hardcoded key to each byte, using the cheeky phrase: ‘look me, AV!’”
“The threat actors regularly disguise their control domains to impersonate real international technology providers. Specifically, investigators found active domains mimicking major communications brands in Southeast Asia.”
This makes the malware’s own processes completely invisible to standard tools like ps and top... The hardcoded process filter list, which hides entries named “kworkers,” “dbus,” and “autoupdate,” adds yet another layer by mimicking the names of normal system processes.
It collects host details including the system name, operating system information, running processes, and even captures a screenshot.
All of that data gets encrypted, encoded in base64, and hidden inside a PNG image field before being sent out, making the traffic appear completely harmless.
Once Showboat runs on a victim machine, it pulls an encrypted configuration file from its built-in command-and-control server.
“Showboat is a modular post-exploitation framework designed for Linux systems, capable of spawning a remote shell, transferring files and functioning as a Socks5 proxy.”
Showboat is a modular post-exploitation framework designed for Linux systems, capable of spawning a remote shell, transferring files and functioning as a Socks5 proxy... Two other network functions that warranted further exploration were the SOCKS5 and portmap functions.
One notable feature is the “hide” command, which enables a process to conceal itself on a host machine by retrieving code stored on external websites such as Pastebin or online forums for use as a “dead drop.”
When triggered, it fetches a small C source file from a Pastebin page set up by the attackers, compiles it on the victim’s machine...
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux-based malware framework for AMD x86-64 systems that provides stealthy long-term remote access. It retrieves an encrypted configuration, randomizes beaconing, collects host information and screenshots, exfiltrates data hidden in PNG fields, supports file transfer and persistence, and can compile and deploy a rootkit via ld.so.preload to hide its processes from standard monitoring tools.
A modular Linux post-exploitation backdoor/framework used for cyber espionage. It establishes persistent access, spawns remote shells, transfers files, operates as a SOCKS5 proxy, hides its execution path, uses XOR-encrypted configuration data, and collects host information including hostnames, process lists, and desktop screenshots.
Linux-focused post-exploitation malware that provides remote shell access, file upload/download, SOCKS5 proxying, system information collection, encrypted C2 communications, process concealment, and retrieval of code from Pastebin for stealth. It enables attackers to pivot into internal network devices not directly exposed to the internet.
A Linux modular post-exploitation framework/backdoor used to establish footholds on compromised systems. It contacts C2 servers, gathers and exfiltrates system information, supports file upload/download, can spawn a remote shell, acts as a SOCKS5 proxy, hides its presence from the process list, retrieves code from Pastebin for concealment, and can scan for and connect to other devices reachable via LAN.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.