Hackers Use Showboat Post-Exploitation Framework Against Middle East Telecom Firms
ID: 3698152b-9a9a-5a59-9b75-faf5b09254fb
STIX ID: report--3698152b-9a9a-5a59-9b75-faf5b09254fb
Feed Name: Cyber Press
Threat Score
Black Lotus Labs describes Showboat, a stealthy, modular ELF x86-64 Linux backdoor used since mid-2022 against Middle East telecommunications providers, attributed with moderate-to-high confidence to PRC-backed actors; it features XOR-protected configs, randomized beaconing, PNG-disguised exfil, and an ld.so.preload-based hide capability compiled on-host from Pastebin code, enabling long-term undetected access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
