Black Lotus Labs hero image

Introducing Showboat: A new malware family taunts defenses and targets international telecom firms

Black Lotus Labs found SHOWBOAT, a stealthy malware family that targeted telecom firms in Southeast Asia and the Middle East in summer 2024. It spread through trojanized Palo Alto update packages and aimed to keep long-term access. Two variants emerged. The first acted as a downloader and staging implant. The second added command execution, tunneling, keylogging, and credential theft. Metadata points to a Russian-language development setup and possible ties to GOFFEE, though the evidence is not conclusive. Defenders should verify update package integrity and watch for process injection and unusual C2 traffic.

Published on May 21, 2026 | 11 minute read