{"id":27756,"date":"2026-05-24T23:48:41","date_gmt":"2026-05-24T20:18:41","guid":{"rendered":"https:\/\/fajr.news\/?p=27756"},"modified":"2026-05-24T23:48:41","modified_gmt":"2026-05-24T20:18:41","slug":"showboat-linux-malware-targets-middle-east-telecoms-with-socks5-proxy-backdoor","status":"publish","type":"post","link":"https:\/\/fajr.news\/?p=27756&lang=en","title":{"rendered":"Showboat Linux Malware Targets Middle East Telecoms with SOCKS5 Proxy Backdoor"},"content":{"rendered":"<p>Cybersecurity experts have unveiled a sophisticated new Linux malware, dubbed &#8216;Showboat,&#8217; which has been actively deployed in a targeted campaign against a telecommunications provider in the Middle East since at least mid-2022. This discovery highlights the persistent and evolving threats facing critical infrastructure in the region.<\/p>\n<p>According to a report from Lumen Technologies&#8217; Black Lotus Labs, shared with The Hacker News, Showboat is a &#8216;modular post-exploitation framework designed for Linux systems.&#8217; Its capabilities are extensive, including the ability to spawn remote shells, facilitate file transfers, and operate as a SOCKS5 proxy, offering attackers a versatile tool for maintaining control and expanding their reach within compromised networks.<\/p>\n<p>Investigators believe the malware is being utilized by at least one, and potentially more, threat activity clusters with ties to China. This assessment is supported by correlations found between the command-and-control (C2) nodes and IP addresses geolocated to Chengdu, the capital of China&#8217;s Sichuan province. Among the suspected actors is Calypso, also known as Bronze Medley and Red Lamassu, a group with a history of targeting state institutions in countries such as Brazil, India, Kazakhstan, Russia, Thailand, and Turkey since September 2016.<\/p>\n<p>Calypso&#8217;s arsenal is known to include potent tools like PlugX and various backdoors such as WhiteBird and BYEBY, the latter being part of a larger cluster tracked by ESET under the name Mikroceen. The use of Mikroceen has been linked to a group called SixLittleMonkeys, which, in turn, exhibits tactical overlaps with another China-linked entity, Webworm. This pattern suggests Showboat is part of a broader &#8216;resource pooling&#8217; strategy, where multiple China-nexus groups share frameworks like PlugX, ShadowPad, and NosyDoor, indicating a potential &#8216;digital quartermaster&#8217; supplying state-sponsored threat actors with necessary tools.<\/p>\n<p>The investigation into Showboat began with an ELF binary uploaded to VirusTotal in May 2023. The malware scanning platform identified it as a sophisticated Linux backdoor with rootkit-like capabilities, a threat Kaspersky is tracking as EvaRAT.<\/p>\n<p>While the exact initial access vector remains unknown, Black Lotus Labs security researcher Danny Adamitis noted that Calypso has historically leveraged ASPX web shells after exploiting vulnerabilities or compromising default remote access accounts. The group was also among the first China-aligned actors to weaponize CVE-2021-26855, a critical Microsoft Exchange Server vulnerability central to the ProxyLogon exploit chain.<\/p>\n<p>Showboat&#8217;s operational mechanics involve contacting a C2 server, collecting system information, and exfiltrating this data back to the server, often encrypted and Base64-encoded within a PNG field. It can also upload and download files, conceal its presence from process lists, and manage multiple C2 servers. To further evade detection, the malware retrieves a code snippet from Pastebin, a paste created on January 11, 2022. Crucially, Showboat can scan for and connect to other devices via its SOCKS5 proxy, underscoring its primary objective: establishing a deep foothold on compromised systems, particularly those not publicly exposed to the internet but accessible via the local area network (LAN).<\/p>\n<p>Further infrastructure analysis has revealed two confirmed victims: an internet service provider (ISP) based in Afghanistan and another unidentified entity in Azerbaijan. A secondary C2 cluster, employing X.509 certificates similar to the original C2 server, has also indicated potential compromises in the United States and Ukraine.<\/p>\n<p>Adamitis emphasized the dual nature of current cyber threats, stating, &#8216;While some threat actors are increasingly using stealthy, native system tools to evade detection, others still deploy persistent malware implants.&#8217; He warned that &#8216;The presence of such threats should be taken as an early warning sign, indicating the potential for broader and more serious security issues within affected networks.&#8217;<\/p>\n<p>In the campaign targeting the Afghan telecommunications provider, Calypso also deployed JFMBackdoor, a fully featured Windows implant delivered via DLL side-loading. This attack chain involves a batch script launching a legitimate executable that then loads the malicious DLL. JFMBackdoor offers extensive capabilities, including remote shell access, file operations, network proxying, screenshot capture, and self-removal, further demonstrating the group&#8217;s advanced toolkit.<\/p>\n<p>PricewaterhouseCoopers (PwC) corroborated these findings in a coordinated report, asserting that &#8216;The targeting of Afghanistan and its telecommunications sector aligns with what we assess to almost certainly be Red Lamassu&#8217;s wider operational goals and objectives.&#8217;<\/p>\n<p>#Cybersecurity #LinuxMalware #Showboat #SOCKS5Proxy #MiddleEastCyberattack #ChinaThreatActors #Calypso #TelecomSecurity #CyberEspionage #BlackLotusLabs<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity experts have unveiled a sophisticated new Linux malware, dubbed &#8216;Showboat,&#8217; which has been actively deployed in a targeted campaign against a telecommunications provider in the Middle East since at least mid-2022. This discovery highlights the persistent and evolving threats facing critical infrastructure in the region. According to a report from Lumen Technologies&#8217; Black Lotus [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":27757,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[33],"tags":[],"class_list":["post-27756","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-middle-east-news"],"_links":{"self":[{"href":"https:\/\/fajr.news\/index.php?rest_route=\/wp\/v2\/posts\/27756","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fajr.news\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fajr.news\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fajr.news\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/fajr.news\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=27756"}],"version-history":[{"count":0,"href":"https:\/\/fajr.news\/index.php?rest_route=\/wp\/v2\/posts\/27756\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/fajr.news\/index.php?rest_route=\/wp\/v2\/media\/27757"}],"wp:attachment":[{"href":"https:\/\/fajr.news\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=27756"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fajr.news\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=27756"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fajr.news\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=27756"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}