Briefing

Chinese Hackers Target Telcos with Showboat and JFMBackdoor Malware

security
by [email protected] (The Hacker News) ·

Patch Linux systems and monitor for remote shell activity to defend against Showboat malware.

What to do now

Patch Linux systems and monitor for remote shell activity to defend against Showboat malware.

Summary

A Chinese state‑sponsored cyber‑espionage campaign, attributed to the Calypso (Red Lamassu) threat group, has been targeting telecommunications operators across the Asia Pacific and parts of the Middle East since mid‑2022. The attackers employ two complementary malware families: Showboat, a modular post‑exploitation framework for Linux systems, and JFMBackdoor, a Windows implant that delivers reverse shell access, file management, and a range of anti‑forensics capabilities.

Showboat gathers host information, uploads and downloads files, and hides its process. It establishes persistence by creating a new service and can act as a SOCKS5 proxy and port‑forwarding pivot point, enabling attackers to move laterally within the network. JFMBackdoor provides reverse shell access, file management, TCP proxying, process and service management, registry manipulation, screenshot capture, encrypted configuration, and self‑removal/anti‑forensics features. The Windows infection chain begins with a batch script that drops fltMC.exe and FLTLIB.dll before installing the JFMBackdoor payload.

The threat actors use telecom‑themed domains to impersonate their targets, making the initial delivery appear legitimate. The malware has been observed compromising several Middle Eastern telecom providers and a range of operators in the Asia Pacific region. The use of a SOCKS5 proxy indicates a focus on stealthy lateral movement and data exfiltration.

Security experts recommend strict network segmentation, continuous monitoring for SOCKS5 proxy activity, and deployment of endpoint detection and response solutions to mitigate the threat. Organizations should also keep their operating systems and software up to date and restrict the use of untrusted scripts and executables.

The campaign underscores the growing sophistication of Chinese cyber‑espionage operations and the vulnerability of critical infrastructure. Telecom operators must remain vigilant and adopt a layered security approach to defend against Showboat and JFMBackdoor.

Key changes

  • Showboat is modular post‑exploitation Linux malware
  • Can spawn remote shell, transfer files, act as SOCKS5 proxy
  • Targeted Middle Eastern telecom provider since mid‑2022
  • Disclosed by Lumen Security
  • Designed to be highly adaptable to different Linux distributions
  • Observed in wild for over a year

Affects

none

Source angles · 2 perspectives

The Hacker News
Independent angle

Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor

Open
Bleeping Computer
Independent angle

Chinese hackers target telcos with new Linux, Windows malware

Open

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting