- Joined
- Jan 20, 2026
- Messages
- 345
- Reaction score
- 2,235
The Chinese cyber espionage campaign, which has been ongoing since 2019, has been revealed.
The Chinese group Red Lamassu has been entrenched in the telecommunications networks of Asia for years, and now experts have linked its operations with two malicious tools - Linux-harm carrier Showboat and Windows-backdoor JFMBackdoor. Both tools help attackers not just get into the network, but to stay inside, transfer files, run commands and make their way to internal systems that are not available from the Internet.
Showboat has discovered the Black Lotus Labs team of Lumen. According to her, the malware for Linux has been used since at least mid-2022. When the sample was loaded into VirusTotal in May 2025, antiviruses did not detect, and by April 2026, malware was again undetectable.
By launching, Showboat contacts the control server, receives settings, collects information about the infected system, takes a screenshot and sends data to operators. The malware can hide its own process from administrators, transfer files, be fixed as a service, change control servers and work as a proxy SOCKS5. This feature is especially dangerous for telecommunications companies because it gives attackers access to internal nodes of the network.
Black Lotus Labs believes that Showboat has used one or more groups related to China’s interests. The campaign affected the telecommunications provider in the Middle East, and the infrastructure of intruders mimiced
The second report prepared by PwC Threat Intelligence links the same activity with the Red Lamassu group, also known as Calypso. According to PwC, the group has been operating at least since 2019 and is attacking telecommunications and state organizations in the Asia-Pacific region, primarily in Kazakhstan, Afghanistan and India.
PwC found an open directory on the server 23.27.201[.]160, where files lay to infect Windows systems, as well as a sample of Linux-harm kaworker, which Lumen calls Showboat. The main Windows tool is called JFMBackdoor. The malware was started through the DLL substrate and gave operators a wide range of features: work in a remote command line, work with files, proxy network connections, take screenshots, control processes and services, change the Windows registry and delete your own footprints.
The relationship between the two reports reinforces the overall infrastructure. In particular, specialists of both companies found the same self-signed certificates with Metadata “My Organization”, as well as intersections in domains and control servers. One of the nodes that could be a higher server or developer test environment pointed to the China Unicom network and roughly geographically correlated with the Chenglu area.
Telecommunications companies remain a particularly attractive target for state groups. Through such networks pass voice data, Internet traffic and service connections of many organizations, so if attackers hack into one provider, this will allow them to move on. In the case of Red Lamassu, experts see a long campaign where Linux servers, routers and Windows systems are used as reference points to conduct exploration and penetrate deeper.
The Chinese group Red Lamassu has been entrenched in the telecommunications networks of Asia for years, and now experts have linked its operations with two malicious tools - Linux-harm carrier Showboat and Windows-backdoor JFMBackdoor. Both tools help attackers not just get into the network, but to stay inside, transfer files, run commands and make their way to internal systems that are not available from the Internet.
Showboat has discovered the Black Lotus Labs team of Lumen. According to her, the malware for Linux has been used since at least mid-2022. When the sample was loaded into VirusTotal in May 2025, antiviruses did not detect, and by April 2026, malware was again undetectable.
By launching, Showboat contacts the control server, receives settings, collects information about the infected system, takes a screenshot and sends data to operators. The malware can hide its own process from administrators, transfer files, be fixed as a service, change control servers and work as a proxy SOCKS5. This feature is especially dangerous for telecommunications companies because it gives attackers access to internal nodes of the network.
Black Lotus Labs believes that Showboat has used one or more groups related to China’s interests. The campaign affected the telecommunications provider in the Middle East, and the infrastructure of intruders mimiced
The second report prepared by PwC Threat Intelligence links the same activity with the Red Lamassu group, also known as Calypso. According to PwC, the group has been operating at least since 2019 and is attacking telecommunications and state organizations in the Asia-Pacific region, primarily in Kazakhstan, Afghanistan and India.
PwC found an open directory on the server 23.27.201[.]160, where files lay to infect Windows systems, as well as a sample of Linux-harm kaworker, which Lumen calls Showboat. The main Windows tool is called JFMBackdoor. The malware was started through the DLL substrate and gave operators a wide range of features: work in a remote command line, work with files, proxy network connections, take screenshots, control processes and services, change the Windows registry and delete your own footprints.
The relationship between the two reports reinforces the overall infrastructure. In particular, specialists of both companies found the same self-signed certificates with Metadata “My Organization”, as well as intersections in domains and control servers. One of the nodes that could be a higher server or developer test environment pointed to the China Unicom network and roughly geographically correlated with the Chenglu area.
Telecommunications companies remain a particularly attractive target for state groups. Through such networks pass voice data, Internet traffic and service connections of many organizations, so if attackers hack into one provider, this will allow them to move on. In the case of Red Lamassu, experts see a long campaign where Linux servers, routers and Windows systems are used as reference points to conduct exploration and penetrate deeper.