Researchers disclosed Showboat, a previously unreported modular Linux malware framework used since at least mid-2022 to compromise telecommunications organizations in the Middle East, Asia Pacific, and other regions. Black Lotus Labs said the malware operates as a post-exploitation backdoor that enables remote shell access, file transfer, host reconnaissance, persistence, process hiding, port mapping, and SOCKS5 proxying, allowing attackers to maintain access and pivot into internal systems not exposed to the internet. Investigators said the malware stayed largely undetected for months after a 2025 sample submission, highlighting the stealth of Linux-focused intrusions against telecom infrastructure.
Infrastructure and victimology linked the activity with moderate confidence to one or more China-aligned threat clusters, with command-and-control nodes and related IP activity tied to Chengdu, Sichuan, and domains impersonating telecom brands in Southeast Asia. Reporting also connected the broader campaign to the deployment of a Windows implant, JFMBackdoor, through DLL sideloading, suggesting a cross-platform espionage operation against telecom providers. Confirmed or suspected victims included a telecom provider in the Middle East, an ISP in Afghanistan, entities in Azerbaijan, and networks in the United States, Ukraine, and the Donbas region, reinforcing concerns that shared malware tooling is being used across multiple PRC-linked operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers said the Showboat malware campaign has been active since at least mid-2022, targeting telecommunications providers in the Asia Pacific region, the Middle East, and other regions. The activity involved telecom-themed infrastructure and post-exploitation access on Linux systems.
On 2026-05-21, Black Lotus Labs published research on a previously unreported Linux malware family named Showboat, describing it as a modular post-exploitation framework used against telecom organizations. The report linked the activity with moderate confidence to one or more PRC-aligned threat clusters and documented victims in the Middle East, Afghanistan, Azerbaijan, the United States, and the Donbas region.
Lumen reported that a Showboat malware sample submitted on 2025-05-05 remained undetected on VirusTotal through April 2026. The finding highlighted the malware's stealth and the difficulty of detecting Linux-focused intrusions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcesecpod.com
Open sourcescworld.com
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourcelumen.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.