logo

Showboat Malware Uses Pastebin-Hosted C Code to Enable Linux Process Hiding

ID: ad6ec7e4-a326-59bc-80f2-a090c2eb2a4b

STIX ID: report--ad6ec7e4-a326-59bc-80f2-a090c2eb2a4b

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

Author: Mayura Kathir

...
...

Black Lotus Labs and Picus Security analyzed Showboat, a previously undocumented ELF64 Linux remote access framework active since mid‑2022 that targets AMD x86‑64 hosts (notably Middle Eastern telecommunications). Showboat retrieves an XOR‑encrypted config from C2, beacons via PNG ancillary fields, and — for stealth — downloads C source from Pastebin, compiles a shared object, and uses ld.so.preload to hide processes; the report provides indicators (XOR config keying, PNG‑embedded beacons, Pastebin URLs, ld.so.preload writes), attribution details linking infrastructure to Chengdu, and practical detection and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.