threat-intel
Chinese APTs Share Linux Backdoor in Central Asia Telco Attacks
Medium
Summary
This article details the discovery of "Showboat" (kworker), a Linux post-exploitation framework being shared among Chinese Advanced Persistent Threat (APT) groups, primarily Calypso and Red Lamassu. The malware has been used to spy on telecommunications companies in Central Asia, including targets in Afghanistan, Ukraine, and Turkey, highlighting a tactic of quietly gathering geopolitical intelligence. Its relatively simple design and widespread sharing suggest a deliberate strategy for testing and deploying malware in diverse environments.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
