Calypso (Red Lamassu) China-Nexus Telco Espionage — Showboat Linux SOCKS5 Backdoor + JFMBackdoor Windows Implant

Calypso (Red Lamassu) China-Nexus Telco Espionage (TL-2026-0549), also tracked as Red Lamassu, is a high-severity malware campaign, first published 2026-05-21. It is attributed to Calypso (China) with medium confidence, affects Microsoft Windows, maps to 27 MITRE ATT&CK techniques (T1005, T1016, T1027), and is covered by 9 detection rules and 21 indicators of compromise.

Key facts for TL-2026-0549

Threat ID
TL-2026-0549
Also known as
Red Lamassu, Calypso APT
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-05-21
Last reviewed
2026-05-21
Attribution
Calypso
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
telecommunications, internet service providers, managed service providers
Target regions
Asia Pacific, Middle East, Central Asia, South Caucasus, North America, Eastern Europe
Detection rules
9
Indicators of compromise
21

Malware and tooling in Calypso (Red Lamassu) China-Nexus Telco Espionage

Malware and tooling: EvaRAT, JFMBackdoor, Showboat, kworker (Showboat alias), SOCKS5 proxy module (Showboat-embedded), Showboat (custom Calypso framework)

Lumen Black Lotus Labs and PwC Threat Intelligence disclosed an active Chinese cyber-espionage campaign attributed to Calypso (aka Red Lamassu) targeting telecommunications providers in Asia Pacific and the Middle East since at least mid-2022. Operators deploy Showboat — a modular Linux post-exploitation framework with SOCKS5 proxy, port-forwarding, process hiding, and Pastebin dead-drop tasking — alongside JFMBackdoor, a full-featured Windows espionage implant loaded via fltMC.exe + FLTLIB.dll DLL sideloading. Confirmed victims include an Afghan ISP and an Azerbaijani entity, with a secondary C2 cluster sharing X.509 certificates implicating compromises in the United States and Ukraine.

How Calypso (Red Lamassu) China-Nexus Telco Espionage works

OVERVIEW

On 2026-05-21, Lumen Black Lotus Labs and PwC Threat Intelligence jointly disclosed a multi-year Chinese cyber-espionage campaign attributed to the Calypso threat group (tracked by PwC as Red Lamassu). The campaign targets telecommunications carriers and internet service providers across Asia Pacific and the Middle East, leveraging two previously undocumented implants — Showboat (Linux) and JFMBackdoor (Windows) — together with telecom-themed impersonation domains. Black Lotus Labs assesses with moderate-to-high confidence that the tooling is operated by at least one — and likely several — China-aligned activity clusters, with C2 infrastructure correlating to IP geolocations in Chengdu, Sichuan Province, China. Kaspersky tracks an overlapping Linux artifact as EvaRAT, and the toolset shows infrastructure-pattern overlap with PlugX, ShadowPad, and NosyDoor operators.

SHOWBOAT LINUX FRAMEWORK

Showboat (file basename frequently masquerades as kworker, a legitimate Linux kernel thread name) is a modular ELF post-exploitation framework purpose-built for long-term persistence on carrier-grade Linux infrastructure. Capabilities documented across Black Lotus Labs telemetry:

- Host reconnaissance: enumerates kernel version, distribution, network interfaces, running processes, and open ports. - Remote interactive shell: PTY-backed reverse shell with command execution. - File operations: upload, download, deletion, timestomping. - SOCKS5 proxy: full RFC 1928 implementation allowing operators to tunnel arbitrary TCP through the compromised host into otherwise unroutable carrier networks. - TCP port-forwarding: bidirectional relays for lateral movement between segmented subnets. - Network scanner: discovers reachable hosts and integrates results with the SOCKS5 module for pivoting into adjacent network segments not directly reachable from the operator. - Process concealment ('hide' command): retrieves obfuscation/rootkit-style hiding code from external dead-drop locations — most notably a Pastebin paste registered 2022-01-11 — and applies it to conceal Showboat's process from /proc enumeration and process listing tools. - Multi-C2 management: stores a list of primary and fallback C2 endpoints; rotates on failure. - Persistence: installs as a systemd service or sysvinit script under names mimicking legitimate kernel workers (kworker, kthreadd, kauditd). - Beaconing channel: exfiltrates host-survey data as encrypted, Base64-encoded blobs hidden inside PNG image fields posted to attacker-controlled servers, evading mime/extension-based egress filtering.

A pivotal sample (SHA256 d6a4fad5448838dbc8cc6b33f1dbfbdc7a2fad36de58ff6a66dce96f729f7011) was first uploaded to VirusTotal in May 2025 from an unattributed submitter, allowing Black Lotus Labs to retroactively scope the campaign back to mid-2022.

JFMBACKDOOR WINDOWS IMPLANT

PwC's analysis of the Windows infection chain shows Red Lamassu staging JFMBackdoor through a multi-step DLL sideloading sequence:

1. A batch script (delivered post-initial-access) drops three files into a user-writable directory: the legitimate Microsoft-signed fltMC.exe (Filter Manager Control utility), a trojanized FLTLIB.dll proxy DLL, and an encrypted JFMBackdoor payload. 2. The batch script executes fltMC.exe, which lazy-loads FLTLIB.dll from its working directory (Windows default search-order hijack — MITRE T1574.001). 3. The malicious FLTLIB.dll decrypts and reflectively loads the final JFMBackdoor stage into the trusted fltMC.exe process.

JFMBackdoor capabilities:

- Reverse shell access. - File management (read/write/delete/list, recursive directory enumeration). - TCP proxying for lateral movement. - Process and service control (enumerate, kill, create, start, stop). - Registry manipulation (read/write/delete keys and values). - Screen capture. - Encrypted configuration management — C2 endpoints, beacon intervals, and module enablement stored in an encrypted blob refreshed on demand. - Self-removal and anti-forensics — wipes its dropped artifacts, clears prefetch traces, and tampers with USN journal entries on command.

INFRASTRUCTURE AND ATTRIBUTION

Red Lamassu/Calypso operators register telecom-themed impersonation domains that mimic carriers and managed-service providers in the targeted regions, supporting both initial access pretexting and C2 traffic blending. Black Lotus Labs identified a secondary C2 cluster reusing X.509 certificate generation patterns (matching CN/O fields, fixed serial-number prefixes, and shared key-generation entropy) — the cluster expands victimology to at least two probable compromises in the United States and one in Ukraine. Geographic IP correlation against multiple primary C2 nodes places operator activity in Chengdu, Sichuan, China — historically a hub for MSS-aligned offensive cyber operations. PwC assesses Red Lamassu's tooling and tradecraft as overlapping with — but distinct from — PlugX, ShadowPad, and NosyDoor operator clusters, consistent with the broader Chinese state-aligned 'shared digital quartermaster' model in which custom and commodity implants flow between contractor groups serving the MSS.

IMPACT AND SECTOR EXPOSURE

The campaign focuses on the strategic intelligence value of telecommunications providers: lawful intercept platforms, signaling gateways, subscriber databases, roaming partner exchanges, and the SS7/Diameter cores that route subscriber metadata for partner carriers worldwide. A compromised mid-tier carrier is therefore an upstream vantage point onto subscribers of dozens of partner networks, which is consistent with the strategic ROI sought by Chinese intelligence services. The SOCKS5/port-forward design of Showboat is operationally tuned to bridge from the public-facing telecom Linux estate into management VLANs, OSS/BSS systems, and ultimately the operator's Active Directory forest — where JFMBackdoor takes over.

MITRE ATT&CK techniques used in TL-2026-0549

Collection

T1005 Data from Local System; T1113 Screen Capture

Discovery

T1016 System Network Configuration Discovery; T1046 Network Service Discovery; T1057 Process Discovery; T1082 System Information Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1564 Hide Artifacts; T1620 Reflective Code Loading

Exfiltration

T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol

Execution

T1059 Command and Scripting Interpreter; T1569 System Services

Command and Control

T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer; T1132 Data Encoding; T1573 Encrypted Channel

command-and-control

T1090 Proxy

Initial Access

T1190 Exploit Public-Facing Application

Persistence

T1543 Create or Modify System Process

stealth

T1574 Hijack Execution Flow

Resource Development

T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities

Affected products and versions in Calypso (Red Lamassu) China-Nexus Telco Espionage

  • Microsoft — Windows
    Vulnerable versions: Windows 10; Windows 11; Windows Server 2016; Windows Server 2019; Windows Server 2022
  • Linux Foundation — Linux (generic, telecom carrier-grade distributions)
    Vulnerable versions: RHEL 7/8/9; CentOS 7/8; Oracle Linux 7/8; Ubuntu 18.04/20.04/22.04 server; SUSE Linux Enterprise Server 12/15

Remediation for Calypso (Red Lamassu) China-Nexus Telco Espionage

Patches

  • No vendor patch is applicable — exploitation depends on adversary-delivered binaries and abuse of legitimate Windows binaries (fltMC.exe), not on a software vulnerability.
  • Ensure Windows endpoints are fully patched against initial-access vectors typically chained by China-nexus operators (Exchange, ProxyShell-class, Ivanti/Fortinet/SonicWall edge-device CVEs, public-facing application 0-days).

Immediate actions

  • Block known Showboat C2 indicators (Chengdu-geolocated IP ranges, observed telecom-impersonation domains) at perimeter and egress proxies.
  • Hunt for processes named kworker/kthreadd/kauditd that have writable on-disk ELF backing — legitimate kernel workers are kernel threads with no on-disk file.
  • Hunt for fltMC.exe executing from any path other than %SystemRoot%\System32 or %SystemRoot%\SysWOW64, and for any FLTLIB.dll loaded from a non-system directory.
  • Block egress from servers to Pastebin and similar paste sites for production telecom Linux estate; if business-required, alert on every fetch.
  • Inspect outbound PNG uploads from server segments — Showboat exfiltrates Base64+encrypted data inside PNG fields.
  • Search for unauthorized systemd unit files and sysvinit scripts referencing /tmp, /var/tmp, /dev/shm, or user home directories as their ExecStart target.

Workarounds

  • Where possible, remove or restrict fltMC.exe access in standard user contexts on telecom servers — administrative Filter Manager interaction is rare in production.
  • Disable outbound TCP from internal server zones to Pastebin (pastebin.com, paste.ee, pastecode.io, ghostbin.co) and similar dead-drop hosts.

Longer-term hardening

  • Deploy EDR with behavioral DLL-sideloading detections (e.g., Sigma 'Potential System DLL Sideloading From Non System Locations') on every Windows asset.
  • Enable Linux auditd with rules for execve of files under /tmp, /dev/shm, and user home directories, plus systemd-unit-file changes.
  • Implement application allowlisting (AppLocker / WDAC) restricting fltMC.exe and other DLL-hijack-prone binaries to their %SystemRoot% locations.
  • Segment carrier OSS/BSS, lawful-intercept, and signaling cores from the corporate AD forest and from internet-egress paths; require jump-host plus MFA for cross-segment access.
  • Adopt outbound DNS allowlisting on telecom infrastructure VLANs; deny by default for paste sites, dynamic-DNS, and newly-registered domains.
  • Threat-hunt for X.509 certificate reuse patterns characteristic of the Red Lamassu C2 cluster across all internet-facing TLS endpoints inside the enterprise.

Weaknesses (CWE) in Calypso (Red Lamassu) China-Nexus Telco Espionage

CWE-427, CWE-426

Timeline of Calypso (Red Lamassu) China-Nexus Telco Espionage

  • Pastebin paste later used as Showboat 'hide' dead-drop resolver is created by the operators, marking the earliest publicly observable infrastructure artifact.
  • Earliest confirmed Calypso/Red Lamassu Showboat activity against Asia Pacific and Middle East telecom targets, per Lumen Black Lotus Labs telemetry.
  • Secondary C2 cluster — reusing X.509 certificate-generation patterns from the primary cluster — comes online and is later linked to probable compromises in the United States and Ukraine.
  • Black Lotus Labs confirms compromises at an Afghan internet service provider and an Azerbaijani entity through C2 telemetry correlation.
  • Pivotal Showboat sample (SHA256 d6a4fad5448838dbc8cc6b33f1dbfbdc7a2fad36de58ff6a66dce96f729f7011, Kaspersky alias EvaRAT) uploaded to VirusTotal, enabling retroactive scoping of the campaign.
  • Threadlinqs Intelligence ingests TL-2026-0549 for full research, detection engineering, and adversary-emulation simulation.
  • Lumen Black Lotus Labs and PwC Threat Intelligence publicly disclose the Calypso/Red Lamassu campaign, Showboat Linux framework, and JFMBackdoor Windows implant; BleepingComputer and The Hacker News publish coverage.
  • As of 2026-05-29, this remains ACTIVE: disclosed only 8 days prior (2026-05-21) by Lumen Black Lotus Labs and PwC, the China-nexus Calypso/Red Lamassu telco-espionage campaign (Showboat Linux + JFMBackdoor) is ongoing with 3+ year persistence and no takedown, sinkhole, or arrest. Non-CVE malware/tradecraft means no patch applies and techniques stay fully viable.

Sources cited for Calypso (Red Lamassu) China-Nexus Telco Espionage

Threats related to Calypso (Red Lamassu) China-Nexus Telco Espionage

Detection coverage for TL-2026-0549

As of 2026-05-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0549 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats