Showboat: Sophisticated Linux Post-Exploitation Framework Targeting Middle East Telecommunications — Threadlinqs Intelligence
As of 2026-06-28, Showboat: Sophisticated Linux Post-Exploitation Framework Targeting Middle East Telecommunications is a critical-severity malware threat attributed to Calypso (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-0990 · Severity: CRITICAL · Status: ACTIVE · Category: MALWARE
Attribution: Calypso · China · ESPIONAGE
Showboat is a sophisticated Linux ELF 64-bit post-exploitation framework attributed to Calypso (Bronze Medley / Red Lamassu), a PRC-backed APT group. Exclusively targeting AMD x86-64 systems in Middle
Showboat is a purpose-built Linux remote access trojan (RAT) with rootkit capabilities developed and deployed by the Calypso threat group (also tracked as Bronze Medley, Red Lamassu). The malware exclusively targets AMD x86-64 Linux systems used in Middle East telecommunications infrastructure, with confirmed victims in Afghanistan, Azerbaijan, and possible compromises in the United States and Ukraine. The campaign began in mid-2022 and remained undetected for approximately four years, representing a critical intelligence collection operation against critical telecommunications infrastructure. The malware implements sophisticated evasion techniques including dynamic linker hijacking via LD_PRELOAD modification of /etc/ld.so.preload, XOR-encrypted command-and-control beacon obfuscation using the hardcoded key 'look me, AV!', Base64 encoding, and steganographic embedding of exfiltrated data within PNG ancillary fields. Showboat's architectural design emphasizes stealth and operational persistence: it achieves system-level process hiding by hooking core syscalls (readdir, etc.) through injected shared objects, filters beacon execution against hardcoded process name patterns (kworkers, dbus, autoupdate) to blend with legitimate system activity, and supports randomized HTTP beaconing intervals (5-10 seconds standard, 20-25 seconds stealth mode) to evade timing-based detection. The malware retrieves process-hiding source code from Pastebin (C file ukpkmkk.c, originally posted 2022-01-11) and compiles it on-host via gcc into injection-ready shared objects, eliminating pre-compiled binary signatures. Command-and-control occurs over HTTP port 80 to the domain telecom.webredirect[.]org (hosting infrastructure in Chengdu, China), with integrated SOCKS5 proxy functionality enabling lateral movement to non-internet-facing infrastructure within target networks. The threat actor uses a modular command structure supporting file transfers, directory manipulation, remote shell execution, screenshot capture, and multi-stage payload injection. The malware collects system reconnaissance including hostname, OS details, UUID, and running process enumeration, all transmitted through encrypted HTTP POST requests with application-layer XOR encryption. Showboat represents the operational maturity of Calypso (active since 2016, documented by Positive Technologies in October 2019) and its access to custom malware development capabilities. The absence of financial/ransom motives across four years of operation, combined with exclusive targeting of critical telecommunications infrastructure in geopolitically sensitive regions (Afghanistan, Azerbaijan, Middle East), indicates state-sponsored intelligence collection objectives and represents a sustained high-confidence threat to telecommunications networks globally.
Target sectors: telecoms, critical-infrastructure, government-communications
Target regions: Middle East, North Africa, 143 - Central Asia, South Asia
Detections & IOCs
As of 2026-08-15, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, CRITICAL, threat intelligence, cybersecurity, T1566, T1199, T1547, T1574, T1027, T1055, T1564, T1140, T1552, T1082