malware
Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor
High
Summary
A new Linux malware, dubbed Showboat, has been used in a campaign targeting a telecommunications provider in the Middle East since at least 2022. The malware, developed by a China-linked threat actor group known as Calypso, functions as a SOCKS5 proxy backdoor and includes tools like PlugX and WhiteBird. Investigations have revealed the malware's use in compromising systems in Afghanistan, Azerbaijan, the U.S., and Ukraine, highlighting the ongoing threat posed by persistent malware implants.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
