Calypso (Red Lamassu) China-Nexus Telco Espionage — Showboat Linux SOCKS5 Backdoor + JFMBackdoor Windows Implant
Calypso (Red Lamassu) China-Nexus Telco Espionage (TL-2026-0549), also tracked as Red Lamassu, is a high-severity malware campaign, first published 2026-05-21. It is attributed to Calypso (China) with medium confidence, affects Microsoft Windows, maps to 27 MITRE ATT&CK techniques (T1005, T1016, T1027), and is covered by 9 detection rules and 21 indicators of compromise.
Key facts for TL-2026-0549
- Threat ID
- TL-2026-0549
- Also known as
- Red Lamassu, Calypso APT
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-05-21
- Last reviewed
- 2026-05-21
- Attribution
- Calypso
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- telecommunications, internet service providers, managed service providers
- Target regions
- Asia Pacific, Middle East, Central Asia, South Caucasus, North America, Eastern Europe
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in Calypso (Red Lamassu) China-Nexus Telco Espionage
Malware and tooling: EvaRAT, JFMBackdoor, Showboat, kworker (Showboat alias), SOCKS5 proxy module (Showboat-embedded), Showboat (custom Calypso framework)
Lumen Black Lotus Labs and PwC Threat Intelligence disclosed an active Chinese cyber-espionage campaign attributed to Calypso (aka Red Lamassu) targeting telecommunications providers in Asia Pacific and the Middle East since at least mid-2022. Operators deploy Showboat — a modular Linux post-exploitation framework with SOCKS5 proxy, port-forwarding, process hiding, and Pastebin dead-drop tasking — alongside JFMBackdoor, a full-featured Windows espionage implant loaded via fltMC.exe + FLTLIB.dll DLL sideloading. Confirmed victims include an Afghan ISP and an Azerbaijani entity, with a secondary C2 cluster sharing X.509 certificates implicating compromises in the United States and Ukraine.
How Calypso (Red Lamassu) China-Nexus Telco Espionage works
OVERVIEW
On 2026-05-21, Lumen Black Lotus Labs and PwC Threat Intelligence jointly disclosed a multi-year Chinese cyber-espionage campaign attributed to the Calypso threat group (tracked by PwC as Red Lamassu). The campaign targets telecommunications carriers and internet service providers across Asia Pacific and the Middle East, leveraging two previously undocumented implants — Showboat (Linux) and JFMBackdoor (Windows) — together with telecom-themed impersonation domains. Black Lotus Labs assesses with moderate-to-high confidence that the tooling is operated by at least one — and likely several — China-aligned activity clusters, with C2 infrastructure correlating to IP geolocations in Chengdu, Sichuan Province, China. Kaspersky tracks an overlapping Linux artifact as EvaRAT, and the toolset shows infrastructure-pattern overlap with PlugX, ShadowPad, and NosyDoor operators.
SHOWBOAT LINUX FRAMEWORK
Showboat (file basename frequently masquerades as kworker, a legitimate Linux kernel thread name) is a modular ELF post-exploitation framework purpose-built for long-term persistence on carrier-grade Linux infrastructure. Capabilities documented across Black Lotus Labs telemetry:
- Host reconnaissance: enumerates kernel version, distribution, network interfaces, running processes, and open ports. - Remote interactive shell: PTY-backed reverse shell with command execution. - File operations: upload, download, deletion, timestomping. - SOCKS5 proxy: full RFC 1928 implementation allowing operators to tunnel arbitrary TCP through the compromised host into otherwise unroutable carrier networks. - TCP port-forwarding: bidirectional relays for lateral movement between segmented subnets. - Network scanner: discovers reachable hosts and integrates results with the SOCKS5 module for pivoting into adjacent network segments not directly reachable from the operator. - Process concealment ('hide' command): retrieves obfuscation/rootkit-style hiding code from external dead-drop locations — most notably a Pastebin paste registered 2022-01-11 — and applies it to conceal Showboat's process from /proc enumeration and process listing tools. - Multi-C2 management: stores a list of primary and fallback C2 endpoints; rotates on failure. - Persistence: installs as a systemd service or sysvinit script under names mimicking legitimate kernel workers (kworker, kthreadd, kauditd). - Beaconing channel: exfiltrates host-survey data as encrypted, Base64-encoded blobs hidden inside PNG image fields posted to attacker-controlled servers, evading mime/extension-based egress filtering.
A pivotal sample (SHA256 d6a4fad5448838dbc8cc6b33f1dbfbdc7a2fad36de58ff6a66dce96f729f7011) was first uploaded to VirusTotal in May 2025 from an unattributed submitter, allowing Black Lotus Labs to retroactively scope the campaign back to mid-2022.
JFMBACKDOOR WINDOWS IMPLANT
PwC's analysis of the Windows infection chain shows Red Lamassu staging JFMBackdoor through a multi-step DLL sideloading sequence:
1. A batch script (delivered post-initial-access) drops three files into a user-writable directory: the legitimate Microsoft-signed fltMC.exe (Filter Manager Control utility), a trojanized FLTLIB.dll proxy DLL, and an encrypted JFMBackdoor payload. 2. The batch script executes fltMC.exe, which lazy-loads FLTLIB.dll from its working directory (Windows default search-order hijack — MITRE T1574.001). 3. The malicious FLTLIB.dll decrypts and reflectively loads the final JFMBackdoor stage into the trusted fltMC.exe process.
JFMBackdoor capabilities:
- Reverse shell access. - File management (read/write/delete/list, recursive directory enumeration). - TCP proxying for lateral movement. - Process and service control (enumerate, kill, create, start, stop). - Registry manipulation (read/write/delete keys and values). - Screen capture. - Encrypted configuration management — C2 endpoints, beacon intervals, and module enablement stored in an encrypted blob refreshed on demand. - Self-removal and anti-forensics — wipes its dropped artifacts, clears prefetch traces, and tampers with USN journal entries on command.
INFRASTRUCTURE AND ATTRIBUTION
Red Lamassu/Calypso operators register telecom-themed impersonation domains that mimic carriers and managed-service providers in the targeted regions, supporting both initial access pretexting and C2 traffic blending. Black Lotus Labs identified a secondary C2 cluster reusing X.509 certificate generation patterns (matching CN/O fields, fixed serial-number prefixes, and shared key-generation entropy) — the cluster expands victimology to at least two probable compromises in the United States and one in Ukraine. Geographic IP correlation against multiple primary C2 nodes places operator activity in Chengdu, Sichuan, China — historically a hub for MSS-aligned offensive cyber operations. PwC assesses Red Lamassu's tooling and tradecraft as overlapping with — but distinct from — PlugX, ShadowPad, and NosyDoor operator clusters, consistent with the broader Chinese state-aligned 'shared digital quartermaster' model in which custom and commodity implants flow between contractor groups serving the MSS.
IMPACT AND SECTOR EXPOSURE
The campaign focuses on the strategic intelligence value of telecommunications providers: lawful intercept platforms, signaling gateways, subscriber databases, roaming partner exchanges, and the SS7/Diameter cores that route subscriber metadata for partner carriers worldwide. A compromised mid-tier carrier is therefore an upstream vantage point onto subscribers of dozens of partner networks, which is consistent with the strategic ROI sought by Chinese intelligence services. The SOCKS5/port-forward design of Showboat is operationally tuned to bridge from the public-facing telecom Linux estate into management VLANs, OSS/BSS systems, and ultimately the operator's Active Directory forest — where JFMBackdoor takes over.
MITRE ATT&CK techniques used in TL-2026-0549
Collection
T1005 Data from Local System; T1113 Screen Capture
Discovery
T1016 System Network Configuration Discovery; T1046 Network Service Discovery; T1057 Process Discovery; T1082 System Information Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1564 Hide Artifacts; T1620 Reflective Code Loading
Exfiltration
T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol
Execution
T1059 Command and Scripting Interpreter; T1569 System Services
Command and Control
T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer; T1132 Data Encoding; T1573 Encrypted Channel
command-and-control
Initial Access
T1190 Exploit Public-Facing Application
Persistence
T1543 Create or Modify System Process
stealth
Resource Development
T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities
Affected products and versions in Calypso (Red Lamassu) China-Nexus Telco Espionage
- Microsoft — Windows
Vulnerable versions: Windows 10; Windows 11; Windows Server 2016; Windows Server 2019; Windows Server 2022 - Linux Foundation — Linux (generic, telecom carrier-grade distributions)
Vulnerable versions: RHEL 7/8/9; CentOS 7/8; Oracle Linux 7/8; Ubuntu 18.04/20.04/22.04 server; SUSE Linux Enterprise Server 12/15
Remediation for Calypso (Red Lamassu) China-Nexus Telco Espionage
Patches
- No vendor patch is applicable — exploitation depends on adversary-delivered binaries and abuse of legitimate Windows binaries (fltMC.exe), not on a software vulnerability.
- Ensure Windows endpoints are fully patched against initial-access vectors typically chained by China-nexus operators (Exchange, ProxyShell-class, Ivanti/Fortinet/SonicWall edge-device CVEs, public-facing application 0-days).
Immediate actions
- Block known Showboat C2 indicators (Chengdu-geolocated IP ranges, observed telecom-impersonation domains) at perimeter and egress proxies.
- Hunt for processes named kworker/kthreadd/kauditd that have writable on-disk ELF backing — legitimate kernel workers are kernel threads with no on-disk file.
- Hunt for fltMC.exe executing from any path other than %SystemRoot%\System32 or %SystemRoot%\SysWOW64, and for any FLTLIB.dll loaded from a non-system directory.
- Block egress from servers to Pastebin and similar paste sites for production telecom Linux estate; if business-required, alert on every fetch.
- Inspect outbound PNG uploads from server segments — Showboat exfiltrates Base64+encrypted data inside PNG fields.
- Search for unauthorized systemd unit files and sysvinit scripts referencing /tmp, /var/tmp, /dev/shm, or user home directories as their ExecStart target.
Workarounds
- Where possible, remove or restrict fltMC.exe access in standard user contexts on telecom servers — administrative Filter Manager interaction is rare in production.
- Disable outbound TCP from internal server zones to Pastebin (pastebin.com, paste.ee, pastecode.io, ghostbin.co) and similar dead-drop hosts.
Longer-term hardening
- Deploy EDR with behavioral DLL-sideloading detections (e.g., Sigma 'Potential System DLL Sideloading From Non System Locations') on every Windows asset.
- Enable Linux auditd with rules for execve of files under /tmp, /dev/shm, and user home directories, plus systemd-unit-file changes.
- Implement application allowlisting (AppLocker / WDAC) restricting fltMC.exe and other DLL-hijack-prone binaries to their %SystemRoot% locations.
- Segment carrier OSS/BSS, lawful-intercept, and signaling cores from the corporate AD forest and from internet-egress paths; require jump-host plus MFA for cross-segment access.
- Adopt outbound DNS allowlisting on telecom infrastructure VLANs; deny by default for paste sites, dynamic-DNS, and newly-registered domains.
- Threat-hunt for X.509 certificate reuse patterns characteristic of the Red Lamassu C2 cluster across all internet-facing TLS endpoints inside the enterprise.
Weaknesses (CWE) in Calypso (Red Lamassu) China-Nexus Telco Espionage
CWE-427, CWE-426
Timeline of Calypso (Red Lamassu) China-Nexus Telco Espionage
- Pastebin paste later used as Showboat 'hide' dead-drop resolver is created by the operators, marking the earliest publicly observable infrastructure artifact.
- Earliest confirmed Calypso/Red Lamassu Showboat activity against Asia Pacific and Middle East telecom targets, per Lumen Black Lotus Labs telemetry.
- Secondary C2 cluster — reusing X.509 certificate-generation patterns from the primary cluster — comes online and is later linked to probable compromises in the United States and Ukraine.
- Black Lotus Labs confirms compromises at an Afghan internet service provider and an Azerbaijani entity through C2 telemetry correlation.
- Pivotal Showboat sample (SHA256 d6a4fad5448838dbc8cc6b33f1dbfbdc7a2fad36de58ff6a66dce96f729f7011, Kaspersky alias EvaRAT) uploaded to VirusTotal, enabling retroactive scoping of the campaign.
- Threadlinqs Intelligence ingests TL-2026-0549 for full research, detection engineering, and adversary-emulation simulation.
- Lumen Black Lotus Labs and PwC Threat Intelligence publicly disclose the Calypso/Red Lamassu campaign, Showboat Linux framework, and JFMBackdoor Windows implant; BleepingComputer and The Hacker News publish coverage.
- As of 2026-05-29, this remains ACTIVE: disclosed only 8 days prior (2026-05-21) by Lumen Black Lotus Labs and PwC, the China-nexus Calypso/Red Lamassu telco-espionage campaign (Showboat Linux + JFMBackdoor) is ongoing with 3+ year persistence and no takedown, sinkhole, or arrest. Non-CVE malware/tradecraft means no patch applies and techniques stay fully viable.
Sources cited for Calypso (Red Lamassu) China-Nexus Telco Espionage
- Chinese hackers target telcos with new Linux, Windows malware
- Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor
- Black Lotus Labs — Public IOC Repository
- Black Lotus Labs — Lumen Technologies (research hub)
- HijackLibs — fltlib.dll DLL hijack entry
- Suspected Chinese Group Calypso APT Exploiting Vulnerable Microsoft Exchange Servers
- MITRE ATT&CK T1574.001 — DLL Search Order Hijacking
Threats related to Calypso (Red Lamassu) China-Nexus Telco Espionage
Detection coverage for TL-2026-0549
As of 2026-05-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0549 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.