logo

Hackers Use Showboat Post-Exploitation Framework Against Middle East Telecom Firms

ID: 3698152b-9a9a-5a59-9b75-faf5b09254fb

STIX ID: report--3698152b-9a9a-5a59-9b75-faf5b09254fb

Feed Name: Cyber Press

Threat Score
88/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

Author: Varshini

...
...

Black Lotus Labs describes Showboat, a stealthy, modular ELF x86-64 Linux backdoor used since mid-2022 against Middle East telecommunications providers, attributed with moderate-to-high confidence to PRC-backed actors; it features XOR-protected configs, randomized beaconing, PNG-disguised exfil, and an ld.so.preload-based hide capability compiled on-host from Pastebin code, enabling long-term undetected access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.