NEWS Linux and Windows are under attack at the same time. Red Lamassu Group Built Invisible Infrastructure Inside Telecom Companies

Gold Surfer

Administrator
Staff member
Administrator
Moon-Club
Exclusive
Infinity
Premium
Member
Joined
Jan 20, 2026
Messages
345
Reaction score
2,235
The Chinese cyber espionage campaign, which has been ongoing since 2019, has been revealed.
The Chinese group Red Lamassu has been entrenched in the telecommunications networks of Asia for years, and now experts have linked its operations with two malicious tools - Linux-harm carrier Showboat and Windows-backdoor JFMBackdoor. Both tools help attackers not just get into the network, but to stay inside, transfer files, run commands and make their way to internal systems that are not available from the Internet.

Showboat has discovered the Black Lotus Labs team of Lumen. According to her, the malware for Linux has been used since at least mid-2022. When the sample was loaded into VirusTotal in May 2025, antiviruses did not detect, and by April 2026, malware was again undetectable.

By launching, Showboat contacts the control server, receives settings, collects information about the infected system, takes a screenshot and sends data to operators. The malware can hide its own process from administrators, transfer files, be fixed as a service, change control servers and work as a proxy SOCKS5. This feature is especially dangerous for telecommunications companies because it gives attackers access to internal nodes of the network.

Black Lotus Labs believes that Showboat has used one or more groups related to China’s interests. The campaign affected the telecommunications provider in the Middle East, and the infrastructure of intruders mimiced
The second report prepared by PwC Threat Intelligence links the same activity with the Red Lamassu group, also known as Calypso. According to PwC, the group has been operating at least since 2019 and is attacking telecommunications and state organizations in the Asia-Pacific region, primarily in Kazakhstan, Afghanistan and India.

PwC found an open directory on the server 23.27.201[.]160, where files lay to infect Windows systems, as well as a sample of Linux-harm kaworker, which Lumen calls Showboat. The main Windows tool is called JFMBackdoor. The malware was started through the DLL substrate and gave operators a wide range of features: work in a remote command line, work with files, proxy network connections, take screenshots, control processes and services, change the Windows registry and delete your own footprints.

The relationship between the two reports reinforces the overall infrastructure. In particular, specialists of both companies found the same self-signed certificates with Metadata “My Organization”, as well as intersections in domains and control servers. One of the nodes that could be a higher server or developer test environment pointed to the China Unicom network and roughly geographically correlated with the Chenglu area.

Telecommunications companies remain a particularly attractive target for state groups. Through such networks pass voice data, Internet traffic and service connections of many organizations, so if attackers hack into one provider, this will allow them to move on. In the case of Red Lamassu, experts see a long campaign where Linux servers, routers and Windows systems are used as reference points to conduct exploration and penetrate deeper.
 

BLACK VEIL

Well-known member
Member
Joined
Jul 29, 2026
Messages
56
Reaction score
27
Location
ABD
Website
www.shopier.com
The Chinese cyber espionage campaign, which has been ongoing since 2019, has been revealed.
The Chinese group Red Lamassu has been entrenched in the telecommunications networks of Asia for years, and now experts have linked its operations with two malicious tools - Linux-harm carrier Showboat and Windows-backdoor JFMBackdoor. Both tools help attackers not just get into the network, but to stay inside, transfer files, run commands and make their way to internal systems that are not available from the Internet.

Showboat has discovered the Black Lotus Labs team of Lumen. According to her, the malware for Linux has been used since at least mid-2022. When the sample was loaded into VirusTotal in May 2025, antiviruses did not detect, and by April 2026, malware was again undetectable.

By launching, Showboat contacts the control server, receives settings, collects information about the infected system, takes a screenshot and sends data to operators. The malware can hide its own process from administrators, transfer files, be fixed as a service, change control servers and work as a proxy SOCKS5. This feature is especially dangerous for telecommunications companies because it gives attackers access to internal nodes of the network.

Black Lotus Labs believes that Showboat has used one or more groups related to China’s interests. The campaign affected the telecommunications provider in the Middle East, and the infrastructure of intruders mimiced
The second report prepared by PwC Threat Intelligence links the same activity with the Red Lamassu group, also known as Calypso. According to PwC, the group has been operating at least since 2019 and is attacking telecommunications and state organizations in the Asia-Pacific region, primarily in Kazakhstan, Afghanistan and India.

PwC found an open directory on the server 23.27.201[.]160, where files lay to infect Windows systems, as well as a sample of Linux-harm kaworker, which Lumen calls Showboat. The main Windows tool is called JFMBackdoor. The malware was started through the DLL substrate and gave operators a wide range of features: work in a remote command line, work with files, proxy network connections, take screenshots, control processes and services, change the Windows registry and delete your own footprints.

The relationship between the two reports reinforces the overall infrastructure. In particular, specialists of both companies found the same self-signed certificates with Metadata “My Organization”, as well as intersections in domains and control servers. One of the nodes that could be a higher server or developer test environment pointed to the China Unicom network and roughly geographically correlated with the Chenglu area.

Telecommunications companies remain a particularly attractive target for state groups. Through such networks pass voice data, Internet traffic and service connections of many organizations, so if attackers hack into one provider, this will allow them to move on. In the case of Red Lamassu, experts see a long campaign where Linux servers, routers and Windows systems are used as reference points to conduct exploration and penetrate deeper.
⛧ BLACK VEIL // PRIVATE SERVICES ⛧

“Some requests are never made publicly.”

01 — THE FIXER
Coordination of private requests, connections, and sensitive agreements.
$1,000

02 — THE BROKER
Mediation of communication and negotiation between private parties.
$2,500

03 — THE HANDLER
Management of private files and task processes.
$5,000

04 — THE GHOST
Private agent whose identity and background are kept confidential.
$10,000

05 — THE CLEANER
Control of complex situations and crisis management.
$15,000

06 — THE SPYMASTER
Sensitive information, intelligence analysis, and private investigation services.
$25,000

07 — BLACK CONTRACT
Preparation of highly confidential private agreements.
$50,000

08 — OMEGA ACCESS
BLACK VEIL's highest level exclusive service package.
$100,000

---

⛧ PRIVATE CONTACT

SESSION
"050bbbee83794febed3c001a153cf99f2474b71f0952ba019fc62a1b206401a819"

TELEGRAM
"@Cipher5Network"

"PRIVATE CHANNEL" (https://reference-url-citation.invalid/0)

---

"NO PUBLIC LISTING"
"PRIVATE REQUESTS ONLY"
"ACCESS BY APPROVAL"
"BLACK VEIL // 2026"

STATUS: "ACTIVE"
ACCESS: "RESTRICTED"
CLIENTS: "UNKNOWN"
 

MATRİXELİTES

Well-known member
Member
Joined
Aug 4, 2026
Messages
443
Reaction score
51
The Chinese cyber espionage campaign, which has been ongoing since 2019, has been revealed.
The Chinese group Red Lamassu has been entrenched in the telecommunications networks of Asia for years, and now experts have linked its operations with two malicious tools - Linux-harm carrier Showboat and Windows-backdoor JFMBackdoor. Both tools help attackers not just get into the network, but to stay inside, transfer files, run commands and make their way to internal systems that are not available from the Internet.

Showboat has discovered the Black Lotus Labs team of Lumen. According to her, the malware for Linux has been used since at least mid-2022. When the sample was loaded into VirusTotal in May 2025, antiviruses did not detect, and by April 2026, malware was again undetectable.

By launching, Showboat contacts the control server, receives settings, collects information about the infected system, takes a screenshot and sends data to operators. The malware can hide its own process from administrators, transfer files, be fixed as a service, change control servers and work as a proxy SOCKS5. This feature is especially dangerous for telecommunications companies because it gives attackers access to internal nodes of the network.

Black Lotus Labs believes that Showboat has used one or more groups related to China’s interests. The campaign affected the telecommunications provider in the Middle East, and the infrastructure of intruders mimiced
The second report prepared by PwC Threat Intelligence links the same activity with the Red Lamassu group, also known as Calypso. According to PwC, the group has been operating at least since 2019 and is attacking telecommunications and state organizations in the Asia-Pacific region, primarily in Kazakhstan, Afghanistan and India.

PwC found an open directory on the server 23.27.201[.]160, where files lay to infect Windows systems, as well as a sample of Linux-harm kaworker, which Lumen calls Showboat. The main Windows tool is called JFMBackdoor. The malware was started through the DLL substrate and gave operators a wide range of features: work in a remote command line, work with files, proxy network connections, take screenshots, control processes and services, change the Windows registry and delete your own footprints.

The relationship between the two reports reinforces the overall infrastructure. In particular, specialists of both companies found the same self-signed certificates with Metadata “My Organization”, as well as intersections in domains and control servers. One of the nodes that could be a higher server or developer test environment pointed to the China Unicom network and roughly geographically correlated with the Chenglu area.

Telecommunications companies remain a particularly attractive target for state groups. Through such networks pass voice data, Internet traffic and service connections of many organizations, so if attackers hack into one provider, this will allow them to move on. In the case of Red Lamassu, experts see a long campaign where Linux servers, routers and Windows systems are used as reference points to conduct exploration and penetrate deeper.
 

DARKWEB16 layers

Well-known member
Member
Joined
Aug 5, 2026
Messages
161
Reaction score
0
The Chinese cyber espionage campaign, which has been ongoing since 2019, has been revealed.
The Chinese group Red Lamassu has been entrenched in the telecommunications networks of Asia for years, and now experts have linked its operations with two malicious tools - Linux-harm carrier Showboat and Windows-backdoor JFMBackdoor. Both tools help attackers not just get into the network, but to stay inside, transfer files, run commands and make their way to internal systems that are not available from the Internet.

Showboat has discovered the Black Lotus Labs team of Lumen. According to her, the malware for Linux has been used since at least mid-2022. When the sample was loaded into VirusTotal in May 2025, antiviruses did not detect, and by April 2026, malware was again undetectable.

By launching, Showboat contacts the control server, receives settings, collects information about the infected system, takes a screenshot and sends data to operators. The malware can hide its own process from administrators, transfer files, be fixed as a service, change control servers and work as a proxy SOCKS5. This feature is especially dangerous for telecommunications companies because it gives attackers access to internal nodes of the network.

Black Lotus Labs believes that Showboat has used one or more groups related to China’s interests. The campaign affected the telecommunications provider in the Middle East, and the infrastructure of intruders mimiced
The second report prepared by PwC Threat Intelligence links the same activity with the Red Lamassu group, also known as Calypso. According to PwC, the group has been operating at least since 2019 and is attacking telecommunications and state organizations in the Asia-Pacific region, primarily in Kazakhstan, Afghanistan and India.

PwC found an open directory on the server 23.27.201[.]160, where files lay to infect Windows systems, as well as a sample of Linux-harm kaworker, which Lumen calls Showboat. The main Windows tool is called JFMBackdoor. The malware was started through the DLL substrate and gave operators a wide range of features: work in a remote command line, work with files, proxy network connections, take screenshots, control processes and services, change the Windows registry and delete your own footprints.

The relationship between the two reports reinforces the overall infrastructure. In particular, specialists of both companies found the same self-signed certificates with Metadata “My Organization”, as well as intersections in domains and control servers. One of the nodes that could be a higher server or developer test environment pointed to the China Unicom network and roughly geographically correlated with the Chenglu area.

Telecommunications companies remain a particularly attractive target for state groups. Through such networks pass voice data, Internet traffic and service connections of many organizations, so if attackers hack into one provider, this will allow them to move on. In the case of Red Lamassu, experts see a long campaign where Linux servers, routers and Windows systems are used as reference points to conduct exploration and penetrate deeper.
Telegram Join our Telegram channel! Welcome to our Telegram channel, blacks Join our Telegram channel, blacks room! Welcome to our Telegram channel, Blacks Room continues to grow! Welcome to our Telegram channel, Blacks Room continues to grow! 186 Welcome to our Telegram channel, Blacks Room! We continue to grow and have 186 members. Welcome to our Telegram channel, Blacks Room! We continue to grow, we have 186 members and entries are welcome. Welcome to our Telegram channel, Blacks Room! We're growing, we have 186 members, and entry is free. Welcome to our Telegram channel, Blacks Room! We continue to grow, we have 186 members and entry is free. Welcome to our Telegram channel, Blacks Room! We continue to grow, we have 186 members, and entry is free, but you need to send messages. Welcome to our Telegram channel, Blacks Room! We continue to grow, we have 186 members, and entry is free, but we have strict moderators for messaging. Welcome to our Telegram channel, Blacks Room! We continue to grow, we have 186 members, and entry is free, but we've implemented strict measures for sending messages. Welcome to our Telegram channel, Blacks Room! We continue to grow, we have 186 members, and entry is free, but we've implemented strict measures for sending messages. 35 35,000 35,000 Telegrams Pay 35,000 Telegram stars and then send a message. You can pay 35,000 Telegram stars and then send a message. You can pay 35,000 Telegram stars and then send a message. You can pay 35,000 Telegram stars and then send messages. This Telegram feature is only for legitimate sellers. You can pay 35,000 Telegram stars and then send messages. This Telegram is only for legitimate sellers. You can pay 35,000 Telegram stars and then send a message. This Telegram account is only for legitimate sellers and secure shopping. You can pay 35,000 Telegram stars and then send a message. This Telegram app is only for legitimate sellers and secure shopping. You can pay 35,000 Telegram stars and then send a message. This Telegram account is only for legitimate sellers and secure transactions. You can pay 35,000 Telegram stars and then send a message. This Telegram account is only for legitimate sellers and secure transactions. Now Now he's a scammer. No more scams We are putting an end to these scams now. We are putting an end to scams now, Blacks Room is safe. We are putting an end to scams; shop safely at Blacks Room. We are putting an end to scams; Blacks Room allows you to shop safely. We are putting an end to scams; Blacks Room allows you to shop safely.

 
5,534Threads
74,882Messages
5,795Members
Morgan RogersLatest member
Top Bottom