Showboat: new Linux malware targeting telecom providers

Lumen reports the discovery of Showboat, a new Linux-based malware family used in targeted attacks against international telecommunications providers. The malware appears built for post-compromise access, letting attackers maintain persistence, execute commands and move within telecom environments while evading detection.

Its use in telecom-focused intrusions suggests a sustained effort to gain visibility into or control over sensitive communications infrastructure.

What this means for your business

Telecom is critical infrastructure and falls under NIS2 as an essential entity. But the consequences do not stop there: every organisation depends on an operator, and a breach at the operator affects customer communications without the customer having done anything wrong. For the board this is about knowing which suppliers the organisation genuinely cannot operate without, and what the plan is if one of them is compromised.

Berigo recommends

  • Identify which communications providers you are critically dependent on, and obtain their incident notification procedures in writing.
  • Ensure sensitive communications are protected end to end, so the operator network is not a point of trust.
  • Establish an alternative communication channel for crisis management that does not depend on the same operator.
  • Add the compromised telecom provider scenario to your continuity exercises.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch