Adversary Intelligence — 2026-05-23

Lumen Black Lotus Labs Exposes Chinese Showboat Malware Family Targeting Middle East Telecom Providers Since 2022

BLUFThree years of undetected access to regional telecom backbones gives Beijing a pre-positioned espionage platform whose true victim count almost certainly exceeds the handful confirmed so far.

Lumen Black Lotus Labs on May 21 disclosed Showboat, a previously unreported Linux malware framework targeting telecommunications providers since at least mid-2022, with remote shell access, file transfer, and SOCKS5 proxy capabilities; the malware registered zero detections on VirusTotal when first submitted and reportedly remained undetected through April 2026 12. Black Lotus correlated C2 nodes to Chengdu-geolocated IP addresses, including one resolving to China Unicom, and attributed the tooling to at least one, and likely several, PRC-aligned clusters observed sharing the tool across dissimilar targets; The Hacker News and BleepingComputer identify Calypso, also tracked as Red Lamassu and assessed as likely operating out of Sichuan Province, as one such actor 123. Confirmed victims include an Afghanistan-based ISP and an Azerbaijani entity, with secondary C2 analysis surfacing possible compromises in the United States and Ukraine 12. PwC Threat Intelligence, in a coordinated release with Black Lotus, documented a companion Windows implant called JFMBackdoor deployed via DLL side-loading against telecommunications targets in Afghanistan, with capabilities including remote shell, file system operations, network proxying, screenshot capture, and self-removal 234.

Analysis
Telecom operators across Central Asia and the Middle East are running infrastructure that PRC-aligned actors have weaponized as lateral movement platforms for at least three years. SOCKS5 and portmapping capabilities turn a single infected host into a pivot into internal network segments, leaving downstream customers and peering partners with inherited exposure invisible to their own teams. A Chengdu-geolocated C2 resolving to China Unicom and coordinated deployment of Windows implant JFMBackdoor point to deliberate dual-platform tradecraft. With no independent corroboration of Black Lotus's findings, Showboat may be a contracted or underground-market framework independently adopted by multiple actors rather than a state-directed capability with unified tasking. Secondary C2 analysis places suspected compromises in the United States and Ukraine.
4 sources
  1. Introducing Showboat: A new malware family taunts defenses and targets international telecom firms - Lumen Black Lotus Labs
  2. Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor - The Hacker News
  3. Chinese hackers target telcos with new Linux, Windows malware - BleepingComputer
  4. New 'Showboat' malware tied to China-linked telecom espionage - CyberNews

View in full brief →

UNCLASSIFIED // OPEN SOURCE