Tag: Middle East Telecom

Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor
News

Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor

A new Linux malware known as Showboat has been used in a campaign against a Middle Eastern telecom company since at least mid-2022, according to information released by cybersecurity researchers. According to a report provided with The Hacker News by Lumen Technologies Black Lotus Labs, Showboat is a modular post-exploitation framework for Linux systems that can transfer files, launch a remote shell, and operate as a SOCKS5 proxy. Correlations between command-and-control (C2) nodes and IP addresses geolocated to Chengdu, the capital city of the Chinese province of Sichuan, indicate that the malware has been used by at least one, and potentially more, threat activity clusters associated with China. Targeting governmental institutions in Brazil, India, Kazakhstan, Russia, Thailand,...