Showboat: Chinese-Linked Hackers Deploy Stealthy Linux Framework Against Middle East Telecoms

Black Lotus Labs has uncovered Showboat, a stealthy Linux post-exploitation framework active since 2022 and linked with moderate-to-high confidence to Chinese state-backed actors. Primary targets: telecom operators in the Middle East. Zero detections on VirusTotal for nearly two years.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region5 min read
Telecommunications hardware in a data centre corridor, representing the Showboat Linux post-exploitation framework used by Chinese-linked threat actors to target Middle East telecom operators

Telecommunications hardware in a data centre corridor, representing the Showboat Linux post-exploitation framework used by Chinese-linked threat actors to target Middle East telecom operators

A sophisticated Linux post-exploitation framework that evaded detection for nearly two years has been identified targeting telecommunications companies in the Middle East, according to research published by Black Lotus Labs, the threat intelligence unit of Lumen Technologies. The framework, named Showboat, has been active since at least mid-2022 and is attributed with moderate-to-high confidence to threat actors backed by the People's Republic of China.

The attribution rests on command-and-control infrastructure traced to Chengdu, China, and on tactical and technical overlap with other documented Chinese advanced persistent threat groups. When first uploaded to VirusTotal in May 2025, Showboat registered a zero detection rate across 65 security engines, and it remained undetected in the wild until April 2026, a span of roughly three years from its earliest known activity.

How Showboat Operates

Showboat is compiled as an ELF 64-bit executable targeting AMD x86-64 Linux systems. It is not a dropper or ransomware variant but a modular framework designed to provide operators with sustained, quiet access to compromised networks over extended periods.

On execution, the malware contacts its built-in command-and-control server to retrieve a configuration file. That file is encrypted using XOR with the hardcoded key "look me, AV!" and contains parameters for server communication including randomised sleep intervals between configurable minimum and maximum limits. The randomisation is deliberate: it prevents the malware from generating predictable network traffic patterns that would surface in baseline monitoring.

After the configuration phase, Showboat initiates a heartbeat beacon. It collects host information including the hostname, operating system details, a list of running processes, and a desktop screenshot. This data bundle is encrypted, base64-encoded, and embedded inside a PNG image field before exfiltration to the operator, a steganographic-style concealment approach designed to blend with legitimate image transfer traffic.

The framework includes a set of remote access commands covering file transfers and persistence mechanisms. Its most operationally significant capability is a command described as "hide." When triggered, the framework downloads a C source file from an attacker-controlled Pastebin page, compiles it directly on the victim's machine, and then injects it into the dynamic linker using ld.so.preload. This Linux mechanism, which instructs the loader to preload a shared library before all others, allows Showboat to hook system calls and conceal specific processes, including those named kworkers or autoupdate, from standard system monitoring tools such as ps and top.

The result is a framework that can maintain persistent access to a compromised Linux host while hiding the evidence of its own presence from both automated monitoring and manual operator review.

Why Middle East Telecoms Are the Target

Telecommunications companies in the Gulf occupy a uniquely high-value position for state-sponsored intelligence collection. They carry the communications of government ministries, financial institutions, military entities, and the general population simultaneously. A compromise of telecom infrastructure provides access not just to network traffic but to the operational data of every organisation that traverses it.

The Middle East telecom sector has been a sustained target for Chinese-linked groups across the period documented in this research, consistent with the same strategic intelligence priorities that drove the upgraded BPFdoor backdoor campaign targeting telecoms across the Middle East, Asia-Pacific, and Africa, another Chinese APT operation using Linux-based implants and covert command routing specifically designed to evade standard monitoring. The targeting pattern is consistent with broader People's Republic of China strategic intelligence priorities that emphasise long-term access and collection over disruptive operations.

GCC telecoms operating Linux-based infrastructure, including network function virtualisation environments, should treat Showboat's indicators of compromise as an immediate review priority. Organisations using Picus Security's simulation platform can test their detection coverage against Showboat using threat IDs 81500 (network infiltration module) and 45442 (email infiltration module).

Detection and Response Considerations

Because Showboat operates entirely within Linux environments and conceals its processes at the dynamic linker level, conventional endpoint detection that relies on process enumeration will miss active infections where the hide command has been invoked. Defenders should prioritise network-level detection over host-based detection for this threat.

Indicators to monitor include outbound connections to on.aws domains carrying PNG-formatted payloads with anomalously structured binary content, processes spawning compilations of downloaded C source files in temporary directories, unexpected modification of /etc/ld.so.preload, and heartbeat-pattern outbound connections with randomised intervals to a consistent external IP.

Organisations should also conduct a retrospective review of Linux host logs from January 2023 onwards. Given that Showboat operated undetected for approximately three years, historical indicators may be present in environments that have not yet identified an active infection. Any organisation operating telecommunications infrastructure in the UAE, Saudi Arabia, Qatar, Kuwait, Bahrain, or Oman with Linux-based server deployments should treat this as a mandatory review item. Telecommunications operators in the UAE should note that NESA information assurance standards classify telecom infrastructure as critical national infrastructure with mandatory proactive threat monitoring obligations, and a three-year undetected intrusion of the kind Showboat enables would represent a material compliance failure under those standards.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

GCC Telecom CybersecurityChina-Linked Threat ActorsLinux Endpoint SecurityState-Sponsored Cyber Espionage MENA