Calypso, also tracked as Red Lamassu, is a China-linked cyber-espionage threat actor associated with intrusions against government entities, telecommunications providers, and private-sector organizations across the Middle East, South America, Africa, Asia Pacific, and Europe. The group is known for exploiting Microsoft Exchange vulnerabilities, including ProxyLogon, and was assessed to have used those flaws while they were still zero-days. In Exchange-related operations, Calypso compromised email servers of governmental entities in the Middle East and South America and later targeted additional government and private-sector servers in Africa, Asia, and Europe. Calypso has been observed conducting post-compromise espionage activity with web shells, backdoors, credential theft tooling, and modular implants. Reported follow-on activity included deployment of multiple web shells and backdoors as well as Mimikatz to obtain credentials. The group has also been linked to an exclusive Win.NOODLERAT variant identified as Type 0x132A, a full-featured backdoor build assessed to be used only by Calypso among observed clusters. Since at least mid-2022, Calypso has been tied to a campaign against telecommunications providers in the Asia Pacific region and parts of the Middle East. That activity used telecom-themed impersonation infrastructure and malware families including Showboat for Linux and JFMBackdoor for Windows. Showboat is a modular Linux post-exploitation framework used for persistence, host reconnaissance, file transfer, process hiding, SOCKS proxying, and port forwarding to support internal pivoting. JFMBackdoor is a Windows espionage implant delivered through a DLL sideloading chain and supports reverse shell access, file and process management, service manipulation, registry modification, screenshot capture, TCP proxying, encrypted configuration handling, self-removal, and anti-forensics. Overall, Calypso is characterized as a long-term espionage operator focused on access to communications infrastructure and sensitive organizational email environments, with capabilities spanning initial exploitation, persistence, credential access, reconnaissance, lateral-enablement through proxying and tunneling, and sustained post-exploitation on both Windows and Linux systems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
Microsoft released emergency security updates for Microsoft Exchange to fix zero-day vulnerabilities, known as ProxyLogon, used in attacks. These attacks were originally attributed to a China state-sponsored hacking group known as HAFNIUM who used the vulnerabilities to compromise servers, install backdoor web shells, and gain access to internal corporate networks.
Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065
Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065
Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese cyber-espionage campaign targeting telecommunications providers across Asia Pacific and parts of the Middle East using newly discovered Linux and Windows malware for long-term persistence, espionage, proxying, and internal network pivoting.
Listed as one of the China-linked groups that followed early exploitation in the 2021 Microsoft Exchange vulnerability campaign.
Referenced as a China-linked threat group observed exploiting zero-day vulnerabilities in Microsoft Exchange (2021).
Used the full-featured Win.NOODLERAT Type 0x132A, likely as an exclusive version.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.