Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

New Linux malware 'Showboat' targets Middle East telecom provider

A new Linux malware named Showboat, also tracked as EvaRAT, is a sophisticated post-exploitation framework targeting telecommunications providers in the Middle East. It provides attackers with remote shell access, file transfer, SOCKS5 proxy tunneling, and process concealment, retrieving code from Pastebin for stealth. Believed to be operated by Chinese-affiliated threat actors, its presence indicates a significant security risk and potential for broader network compromise.
Read Full Article →

Malware New Linux malware ‘Showboat’ targets Middle East telecom provider May 21, 2026 Share By SC Staff (Adobe Stock) As detailed in The Hacker News, a new Linux malware named Showboat has been identified by Lumen Technologies Black Lotus Labs, actively targeting a telecommunications provider in the Middle East since mid-2022. This sophisticated post-exploitation framework is designed for Linux systems and offers capabilities such as remote shell access, file transfer, and SOCKS5 proxy functionality. Showboat is believed to be utilized by Chinese-affiliated threat actors, with command-and-control infrastructure linked to Chengdu, China. This aligns with the observed "resource pooling" strategy employed by Chinese state-sponsored groups, who leverage shared frameworks like PlugX and ShadowPad. The malware, also tracked as EvaRAT by Kaspersky, operates by contacting a C2 server, collecting system information, and transmitting it encrypted. It can upload and download files, conceal its processes, and manage C2 servers. To maintain stealth, Showboat retrieves code from Pastebin. The malware's SOCKS5 proxy feature allows attackers to access internal network devices not directly exposed to the internet. Investigations have uncovered victims including an ISP in Afghanistan, an entity in Azerbaijan, and potential compromises in the U.S. and Ukraine. The presence of Showboat serves as an early warning for broader security risks within affected networks. Source: The Hacker News SC Staff Related Malware Teenager from Odesa suspected of running infostealer malware operation SC Staff May 21, 2026 The suspect allegedly used information-stealing malware between 2024 and 2025 to infect user devices, aiming to steal browser sessions and account credentials. Malware Microsoft disrupts Fox Tempest malware-signing service SC Staff May 20, 2026 Fox Tempest operated a platform called signspace[.]cloud, which allowed threat actors to obtain short-lived Microsoft-issued certificates via Artifact Signing. Malware REMUS infostealer evolves into sophisticated malware-as-a-service platform SC Staff May 18, 2026 Flare's analysis of 128 posts between February and May 2026 reveals REMUS's aggressive development cycle, mirroring structured software businesses. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Adware You can skip this ad in 5 seconds

Share this article