Showboat Malware Uses Pastebin-Hosted C Code to Enable Linux Process Hiding
ID: ad6ec7e4-a326-59bc-80f2-a090c2eb2a4b
STIX ID: report--ad6ec7e4-a326-59bc-80f2-a090c2eb2a4b
Feed Name: GBHackers
Black Lotus Labs and Picus Security analyzed Showboat, a previously undocumented ELF64 Linux remote access framework active since mid‑2022 that targets AMD x86‑64 hosts (notably Middle Eastern telecommunications). Showboat retrieves an XOR‑encrypted config from C2, beacons via PNG ancillary fields, and — for stealth — downloads C source from Pastebin, compiles a shared object, and uses ld.so.preload to hide processes; the report provides indicators (XOR config keying, PNG‑embedded beacons, Pastebin URLs, ld.so.preload writes), attribution details linking infrastructure to Chengdu, and practical detection and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
