Posts

Showing posts with the label Telecommunications

China-aligned hackers built malware that turns telecom Linux servers into SOCKS5 proxies

Image
Chinese threat actors have been quietly compromising telecommunications providers across the Asia Pacific and the Middle East since at least 2022, and the tools they use are unusually well-suited to the kind of long-haul infrastructure spying you'd expect from a state-aligned group. Researchers at Lumen's Black Lotus Labs and PwC Threat Intelligence published details today of two new implants — Showboat for Linux and JFMBackdoor for Windows — that the Calypso (AKA Red Lamassu) group has been using to turn compromised telco systems into network pivots. Showboat is a modular post-exploitation framework that runs on Linux servers and does the kind of thing that makes sysadmins nervous: it collects host information, maintains persistence through new services, and then opens a SOCKS5 proxy on the compromised machine so attackers can hop deeper into the internal network. It also has a neat trick — a "hide" command that pulls code from dead drops like Pastebin pages, meani...

China-aligned hackers built malware that turns telecom Linux servers into SOCKS5 proxies

Chinese threat actors have been quietly compromising telecommunications providers across the Asia Pacific and the Middle East since at least 2022, and the tools they use are unusually well-suited to the kind of long-haul infrastructure spying you'd expect from a state-aligned group. Researchers at Lumen's Black Lotus Labs and PwC Threat Intelligence published details today of two new implants — Showboat for Linux and JFMBackdoor for Windows — that the Calypso (AKA Red Lamassu) group has been using to turn compromised telco systems into network pivots. Showboat is a modular post-exploitation framework that runs on Linux servers and does the kind of thing that makes sysadmins nervous: it collects host information, maintains persistence through new services, and then opens a SOCKS5 proxy on the compromised machine so attackers can hop deeper into the internal network. It also has a neat trick — a "hide" command that pulls code from dead drops like Pastebin pages, meani...