Skip to main content
Mallory
MalwareUsed by 2 actors

Showboat

Showboat is a modular Linux post-exploitation framework and backdoor used in a long-running cyber-espionage campaign active since at least mid-2022. It is designed for Linux systems, including AMD x86-64 ELF builds, and is intended to maintain persistent access after initial compromise. Reported capabilities include spawning a remote shell, uploading and downloading files, functioning as a SOCKS5 proxy, port mapping/port forwarding, gathering host information, collecting running process data, obtaining desktop screenshots, hiding its own process, swapping command-and-control nodes, and establishing persistence as a service. The malware retrieves an XOR-encrypted configuration file using the hardcoded key phrase "look me, AV!" and sends collected host data to command-and-control infrastructure as an encrypted, Base64-encoded string embedded in a PNG field. Researchers also reported that its hide functionality can retrieve code from external sites such as Pastebin or online forums.

Black Lotus Labs reported that Showboat has been used against telecommunications organizations, including a telecommunications provider in the Middle East, with additional victimology or possible compromises involving an Afghanistan-based ISP, Azerbaijan, the United States, and infrastructure tied to the Donbas/Ukraine region. The campaign used telecom-themed domains impersonating communications providers in Southeast Asia. Black Lotus Labs assessed that Showboat was used by at least one, and likely multiple, PRC-aligned or China-affiliated threat clusters, and separate reporting attributed the broader campaign to Calypso (also known as Red Lamassu). Infrastructure analysis linked parts of the command-and-control ecosystem to Chengdu, China with moderate confidence. The initial infection vector was not determined from the available reporting.

Known infrastructure and indicators mentioned in the reporting include telecom.webredirect[.]org resolving to 139.84.227[.]139; additional command-and-control IPs 194.135.25[.]132, 192.9.141[.]111, 64.176.43[.]209, and 116.169.244[.]208:2096; impersonation domains singtelcom[.]site and kaztelecom[.]shop; and self-signed X.509 certificate SHA256 fingerprints 27df475626aafce2ea1548a9f35efb9ad951298c8b11a6adb3ccdfcd5170c677 and e28a96f983b8605decd2ac1db16ebad5fa741a6aa4e585a38ade0e5ad7d6cec0. The malware has also been referred to as kworker in some reporting, and Kaspersky tracks it as EvaRAT.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Calypso

The Linux implant Calypso uses in these attacks, dubbed Showboat/kworker, is a modular post-exploitation framework built for long-term persistence after initial compromise.

via bleeping computerbleepingcomputer.com
Red Lamassu

The Linux implant Calypso uses in these attacks, dubbed Showboat/kworker, is a modular post-exploitation framework built for long-term persistence after initial compromise.

via bleeping computerbleepingcomputer.com
MITRE ATT&CK

Techniques & procedures

19 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

1 technique
T1059Command and Scripting InterpreterEvidence1

“Showboat is a modular post-exploitation framework designed for Linux systems, capable of spawning a remote shell, transferring files and functioning as a Socks5 proxy.”

Persistence

2 techniques
T1543.002Systemd ServiceEvidence1

Our analysis revealed several pre-built functions that an operator could call. These functions allow the operators to upload and download files to and from the host machine, hide the agent itself from the process list, obtain persistence as a service, and swap out C2 nodes.

T1543.003Windows ServiceEvidence1

establish persistence via a new service

Privilege Escalation

2 techniques
T1543.002Systemd ServiceEvidence1

Our analysis revealed several pre-built functions that an operator could call. These functions allow the operators to upload and download files to and from the host machine, hide the agent itself from the process list, obtain persistence as a service, and swap out C2 nodes.

T1543.003Windows ServiceEvidence1

establish persistence via a new service

Stealth

4 techniques
T1027Obfuscated Files or InformationEvidence1

“The file was XOR-encrypted with a hardcoded key to each byte, using the cheeky phrase: ‘look me, AV!’”

T1036MasqueradingEvidence2

“The threat actors regularly disguise their control domains to impersonate real international technology providers. Specifically, investigators found active domains mimicking major communications brands in Southeast Asia.”

T1564Hide ArtifactsEvidence3

“Furthermore, the core binary features specialized capabilities to hide its execution path from local administrators. For instance, it manipulates local environmental libraries to evade standard detection routines.”

T1564.001Hidden Files and DirectoriesEvidence2

One notable feature is the “hide” command, which enables a process to conceal itself on a host machine by retrieving code stored on external websites such as Pastebin or online forums for use as a “dead drop.”

Discovery

3 techniques
T1057Process DiscoveryEvidence2

“After successful decryption, the agent immediately interrogates the host environment. It collects hostnames, process lists, and desktop screenshots.”

T1082System Information DiscoveryEvidence5

“After successful decryption, the agent immediately interrogates the host environment. It collects hostnames, process lists, and desktop screenshots.”

T1083File and Directory DiscoveryEvidence1

Following extract, it gathers various host configurations, including hostname, operating system information, list of running processes, the process of the agent and a screenshot of the desktop.

Lateral Movement

1 technique
T1021Remote ServicesEvidence3

The actor can first scan for other devices and then connect to them via the Socks5 functionality. The presence of these two functions indicates that the purpose of Showboat is to function as a foothold.

Collection

1 technique
T1113Screen CaptureEvidence2

“After successful decryption, the agent immediately interrogates the host environment. It collects hostnames, process lists, and desktop screenshots.”

Command and Control

7 techniques
T1071Application Layer ProtocolEvidence5

“Our analysis shows a correlation between command-and-control (C2) nodes and connections associated with IP addresses that correlate to Chengdu, China.”

T1090ProxyEvidence4

“Showboat is a modular post-exploitation framework designed for Linux systems, capable of spawning a remote shell, transferring files and functioning as a Socks5 proxy.”

T1090.003Multi-hop ProxyEvidence1

Showboat is a modular post-exploitation framework designed for Linux systems, capable of spawning a remote shell, transferring files and functioning as a Socks5 proxy... Two other network functions that warranted further exploration were the SOCKS5 and portmap functions.

T1102.001Dead Drop ResolverEvidence2

One notable feature is the “hide” command, which enables a process to conceal itself on a host machine by retrieving code stored on external websites such as Pastebin or online forums for use as a “dead drop.”

T1105Ingress Tool TransferEvidence4

Our analysis revealed several pre-built functions that an operator could call. These functions allow the operators to upload and download files to and from the host machine...

T1219Remote Access ToolsEvidence3

Showboat is a modular post-exploitation framework designed for Linux systems, capable of spawning a remote shell, transferring files and functioning as a Socks5 proxy.

T1568Dynamic ResolutionEvidence1

To maintain stealth, Showboat retrieves code from Pastebin.

INDICATORS OF COMPROMISE

IOCs tracked for this family

13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
10 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
3 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
hash.sha256●●●●●●●●●●●●View more in app13 days ago
ip.v4●●●●●●●●●●●●View more in app21 days ago
ip.v4●●●●●●●●●●●●View more in app28 days ago
domain●●●●●●●●●●●●View more in app28 days ago
domain●●●●●●●●●●●●View more in app28 days ago
domain●●●●●●●●●●●●View more in app28 days ago
ACTIVITY FEED

Recent activity

5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

security online infoNews
May 28, 2026
Showboat Linux Malware: New Strategic Threat to Telecoms

A modular Linux post-exploitation backdoor/framework used for cyber espionage. It establishes persistent access, spawns remote shells, transfers files, operates as a SOCKS5 proxy, hides its execution path, uses XOR-encrypted configuration data, and collects host information including hostnames, process lists, and desktop screenshots.

Read more
scworldNews
May 21, 2026
New Linux malware ‘Showboat’ targets Middle East telecom provider | brief | SC Media

Linux-focused post-exploitation malware that provides remote shell access, file upload/download, SOCKS5 proxying, system information collection, encrypted C2 communications, process concealment, and retrieval of code from Pastebin for stealth. It enables attackers to pivot into internal network devices not directly exposed to the internet.

Read more
the hacker newsNews
May 21, 2026
Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor

A Linux modular post-exploitation framework/backdoor used to establish footholds on compromised systems. It contacts C2 servers, gathers and exfiltrates system information, supports file upload/download, can spawn a remote shell, acts as a SOCKS5 proxy, hides its presence from the process list, retrieves code from Pastebin for concealment, and can scan for and connect to other devices reachable via LAN.

Read more
bleeping computerNews
May 21, 2026
Chinese hackers target telcos with new Linux, Windows malware

A Linux modular post-exploitation implant used for long-term persistence. It collects host information, communicates with C2, uploads/downloads files, hides its process, establishes persistence as a service, and provides SOCKS5 proxy and port-forwarding capabilities to support internal movement.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching13

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping19

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.