Chinese Hackers Showboat Linux Malware Telco Campaign | MSSP Advisory

HighCredible Report
DateMay 21, 2026
📋Executive Summary
Chinese threat actors deployed new Linux malware called Showboat and Windows backdoor JFMBackdoor against telecommunications providers in a cyber-espionage campaign. The malware provides persistent access through custom backdoors that communicate with command and control infrastructure. This represents a targeted attack on critical infrastructure with dual-platform capabilities.
⚠️Why It Matters for MSSPs
Your RMM agents and remote access tools running on both Windows and Linux endpoints become attack vectors if this malware family spreads beyond telecom targets. Client networks with mixed Windows and Linux environments face exposure to persistent backdoors that bypass traditional endpoint detection, creating a retention risk if you fail to warn them about cross-platform threats.
📬

Get notified when client-ready advisories like this are published each week.

Join the MSSP Watchlist →
🏷️Threat Category
Nation-State

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.