logo

Chinese APTs Target Telcos with Showboat and JFMBackdoor Malware

ID: 46d7a1bd-6441-5ffa-9863-c98f7fa4e25b

STIX ID: report--46d7a1bd-6441-5ffa-9863-c98f7fa4e25b

Feed Name: ThreatCluster

Threat Score
76/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

...
...

A China-aligned APT tracked as Calypso (aka Red Lamassu) has been targeting telecommunications providers across Central Asia and the Asia Pacific since at least mid-2022 using a Linux post-exploitation framework called Showboat and a Windows backdoor named JFMBackdoor. The campaign employs DLL side-loading, process hiding, SOCKS5 proxying, and telecom-themed infrastructure (including IP 23.27.201.160 and related domains) to establish long-term persistence and intelligence collection; detection and network monitoring are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.