Calypso (Red Lamassu) China-Nexus Telco Espionage — Showboat Linux SOCKS5 Backdoor + JFMBackdoor Windows Implant — Threadlinqs Intelligence
As of 2026-05-30, Calypso (Red Lamassu) China-Nexus Telco Espionage — Showboat Linux SOCKS5 Backdoor + JFMBackdoor Windows Implant is a high-severity malware threat attributed to Calypso (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-0549 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Calypso · China · ESPIONAGE
Lumen Black Lotus Labs and PwC Threat Intelligence disclosed an active Chinese cyber-espionage campaign attributed to Calypso (aka Red Lamassu) targeting telecommunications providers in Asia Pacific
OVERVIEW
On 2026-05-21, Lumen Black Lotus Labs and PwC Threat Intelligence jointly disclosed a multi-year Chinese cyber-espionage campaign attributed to the Calypso threat group (tracked by PwC as Red Lamassu). The campaign targets telecommunications carriers and internet service providers across Asia Pacific and the Middle East, leveraging two previously undocumented implants — Showboat (Linux) and JFMBackdoor (Windows) — together with telecom-themed impersonation domains. Black Lotus Labs assesses with moderate-to-high confidence that the tooling is operated by at least one — and likely several — China-aligned activity clusters, with C2 infrastructure correlating to IP geolocations in Chengdu, Sichuan Province, China. Kaspersky tracks an overlapping Linux artifact as EvaRAT, and the toolset shows infrastructure-pattern overlap with PlugX, ShadowPad, and NosyDoor operators.
SHOWBOAT LINUX FRAMEWORK
Showboat (file basename frequently masquerades as kworker, a legitimate Linux kernel thread name) is a modular ELF post-exploitation framework purpose-built for long-term persistence on carrier-grade Linux infrastructure. Capabilities documented across Black Lotus Labs telemetry:
- Host reconnaissance: enumerates kernel version, distribution, network interfaces, running processes, and open ports.
- Remote interactive shell: PTY-backed reverse shell with command execution.
- File operations: upload, download, deletion, timestomping.
- SOCKS5 proxy: full RFC 1928 implementation allowing operators to tunnel arbitrary TCP through the compromised host into otherwise unroutable carrier networks.
- TCP port-forwarding: bidirectional relays for lateral movement between segmented subnets.
- Network scanner: discovers reachable hosts and integrates results with the SOCKS5 module for pivoting into adjacent network segments not directly reachable from the operator.
- Process concealment ('hide' command): retrieves obfuscation/rootkit-style hiding code from external dead-drop locations — most notably a Pastebin paste registered 2022-01-11 — and applies it to conceal Showboat's process from /proc enumeration and process listing tools.
- Multi-C2 management: stores a list of primary and fallback C2 endpoints; rotates on failure.
- Persistence: installs as a systemd service or sysvinit script under names mimicking legitimate kernel workers (kworker, kthreadd, kauditd).
- Beaconing channel: exfiltrates host-survey data as encrypted, Base64-encoded blobs hidden inside PNG image fields posted to attacker-controlled servers, evading mime/extension-based egress filtering.
A pivotal sample (SHA256 d6a4fad5448838dbc8cc6b33f1dbfbdc7a2fad36de58ff6a66dce96f729f7011) was first uploaded to VirusTotal in May 2025 from an unattributed submitter, allowing Black Lotus Labs to retroactively scope the campaign back to mid-2022.
JFMBACKDOOR WINDOWS IMPLANT
PwC's analysis of the Windows infection chain shows Red Lamassu staging JFMBackdoor through a multi-step DLL sideloading sequence:
1. A batch script (delivered post-initial-access) drops three files into a user-writable directory: the legitimate Microsoft-signed fltMC.exe (Filter Manager Control utility), a trojanized FLTLIB.dll proxy DLL, and an encrypted JFMBackdoor payload.
2. The batch script executes fltMC.exe, which lazy-loads FLTLIB.dll from its working directory (Windows default search-order hijack — MITRE T1574.001).
3. The malicious FLTLIB.dll decrypts and reflectively loads the final JFMBackdoor stage into the trusted fltMC.exe process.
JFMBackdoor capabilities:
- Reverse shell access.
- File management (read/write/delete/list, recursive directory enumeration).
- TCP proxying for lateral movement.
- Process and service control (enumerate, kill, create, start, stop).
- Registry manipulation (read/write/delete keys and values).
- Screen capture.
- Encrypted configuration management — C2 endpoints, beacon intervals, and module enablement stored in an encrypted blob refreshed on demand.
- Self-rem
Weaknesses (CWE)
CWE-427, CWE-426
Target sectors: telecommunications, internet service providers, managed service providers
Target regions: Asia Pacific, Middle East, Central Asia, South Caucasus, North America, Eastern Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583, T1583, T1587, T1588, T1190, T1059, T1059, T1569, T1543, T1543