2026-05-22NOTABLERed Lamassu (Calypso/Bronze Medley): Showboat + JFMBackdoor telco espionage implant pair
Calypso telco espionage campaign
campaign · campaign:calypso-red-lamassu-showboat-jfmbackdoor-linux-windows-telco
Calypso (Red Lamassu / Bronze Medley) telco-espionage campaign deploying the Showboat Linux backdoor and JFMBackdoor for Windows.
Aliases: Red Lamassu, Bronze Medley
Coverage
2
first 2026-05-22 → last 2026-05-22
Latest activity
2026-05-22
Red Lamassu (Calypso/Bronze Medley): Showboat + JFMBackdoor telco espionage implant pair
Peak priority
high
1 high · 1 notable
Targets
telco
sectors: telco · regions: europe, middle-east, apac
Sources cited
4
4 hosts
2026-05-222 appearances2026-05-22
Defender insights
What each entry about Calypso telco espionage campaign tells a defender to do, newest first.
Detection
Story timeline
- 2026-05-22Red Lamassu (Calypso/Bronze Medley): Showboat + JFMBackdoor telco espionage implant pair
- 2026-05-22Calypso/Red Lamassu (Bronze Medley) deploys Showboat (Linux) and JFMBackdoor (Windows) against telecoms, new implant pair disclosed by Lumen Black Lotus Labs and PwC Threat Intelligence
Hunting pivots
ATT&CK techniques (8 across 5 tactics)
8 techniques observed across 2 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- ExecutionCommand and Scripting Interpreter: Unix Shell · Hijack Execution Flow: DLL
- StealthMasquerading: Match Legitimate Resource Name or Location · Hijack Execution Flow: DLL
- CollectionArchive Collected Data
- Command and ControlData Obfuscation: Steganography · Proxy: Internal Proxy · Web Service: Dead Drop Resolver
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-05-22/red-lamassu-calypso-bronze-medley-showboat-jfmbackdoor-telco · ATT&CK page ↗
Execution TA0002
T1059.004Command and Scripting Interpreter: Unix Shell×2
Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges.
Evidence: 2026-05-22/red-lamassu-calypso-bronze-medley-showboat-jfmbackdoor-telco · 2026-05-22/calypso-red-lamassu-bronze-medley-deploys-showboat-linux-and · ATT&CK page ↗
T1574.001Hijack Execution Flow: DLL×2
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-05-22/red-lamassu-calypso-bronze-medley-showboat-jfmbackdoor-telco · 2026-05-22/calypso-red-lamassu-bronze-medley-deploys-showboat-linux-and · ATT&CK page ↗
Stealth TA0005
T1036.005Masquerading: Match Legitimate Resource Name or Location×2
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.
Evidence: 2026-05-22/red-lamassu-calypso-bronze-medley-showboat-jfmbackdoor-telco · 2026-05-22/calypso-red-lamassu-bronze-medley-deploys-showboat-linux-and · ATT&CK page ↗
T1574.001Hijack Execution Flow: DLL×2
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-05-22/red-lamassu-calypso-bronze-medley-showboat-jfmbackdoor-telco · 2026-05-22/calypso-red-lamassu-bronze-medley-deploys-showboat-linux-and · ATT&CK page ↗
Collection TA0009
T1560Archive Collected Data×1
An adversary may compress and/or encrypt data that is collected prior to exfiltration. Compressing the data can help to obfuscate the collected data and minimize the amount of data sent over the network. Encryption can be used to hide information that is being exfiltrated from detection or make exfiltration less conspicuous upon inspection by a defender.
Evidence: 2026-05-22/red-lamassu-calypso-bronze-medley-showboat-jfmbackdoor-telco · ATT&CK page ↗
Command and Control TA0011
T1001.002Data Obfuscation: Steganography×1
Adversaries may use steganographic techniques to hide command and control traffic to make detection efforts more difficult. Steganographic techniques can be used to hide data in digital messages that are transferred between systems. This hidden information can be used for command and control of compromised systems. In some cases, the passing of files embedded using steganography, such as image or document files, can be used for command and control.
Evidence: 2026-05-22/red-lamassu-calypso-bronze-medley-showboat-jfmbackdoor-telco · ATT&CK page ↗
T1090.001Proxy: Internal Proxy×2
Adversaries may use an internal proxy to direct command and control traffic between two or more systems in a compromised environment. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use internal proxies to manage command and control communications inside a compromised environment, to reduce the number of simultaneous outbound network connections, to provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between infected systems to avoid suspicion. Internal proxy connections may use common peer-to-peer (p2p) networking protocols, such as SMB, to better blend in with the environment.
Evidence: 2026-05-22/red-lamassu-calypso-bronze-medley-showboat-jfmbackdoor-telco · 2026-05-22/calypso-red-lamassu-bronze-medley-deploys-showboat-linux-and · ATT&CK page ↗
T1102.001Web Service: Dead Drop Resolver×2
Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers.
Evidence: 2026-05-22/red-lamassu-calypso-bronze-medley-showboat-jfmbackdoor-telco · 2026-05-22/calypso-red-lamassu-bronze-medley-deploys-showboat-linux-and · ATT&CK page ↗
Entries about Calypso telco espionage campaign (2)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- bleepingcomputer.com1 (25%)
- lumen.com1 (25%)
- pwc.com1 (25%)
- thehackernews.com1 (25%)
All cited sources (4)
- bleepingcomputer.comBleepingComputer, 2026-05-21https://www.bleepingcomputer.com/news/security/chinese-hackers-target-telcos-with-new-linux-windows-malware/
- lumen.comLumen Black Lotus Labs, 2026-05-21https://www.lumen.com/blog/en-us/introducing-showboat-a-new-malware-family-taunts-defenses-and-targets-international-telecom-firms
- pwc.comPwC Threat Intelligence, 2026-05-21https://www.pwc.com/gx/en/issues/cybersecurity/cyber-threat-intelligence/red-lamassu-open-season.html
- thehackernews.comThe Hacker News, 2026-05-21https://thehackernews.com/2026/05/showboat-linux-malware-hits-middle-east.html