Skip to main content
Mallory
3 malware familiesExploits CVEs in the wild

Calypso

Also known asCalypso

Calypso is a China-linked threat group, also tracked as Red Lamassu, associated with cyber-espionage activity. Reporting in the provided content links Calypso to exploitation of Microsoft Exchange ProxyLogon vulnerabilities in 2021 and to a later campaign targeting telecommunications providers across the Asia Pacific region and parts of the Middle East since at least mid-2022. In the Exchange activity, ESET reported that Calypso compromised email servers of governmental entities in the Middle East and South America, then targeted additional servers belonging to governmental entities and private companies in Africa, Asia, and Europe. The content states Calypso likely had access to the Exchange exploit as a zero-day. ESET also reported Calypso used two web shells and two backdoors and installed Mimikatz tooling to steal credentials. The telecom-focused espionage campaign attributed to Calypso/Red Lamassu used telecom-themed domains to impersonate targets. On Linux, the group deployed Showboat (also referred to as kworker), a modular post-exploitation framework used for persistence, host reconnaissance, file upload/download, process hiding, service creation, SOCKS5 proxying, port forwarding, and retrieving code from external dead-drop sites. On Windows, the group used a batch-script-driven DLL sideloading chain involving fltMC.exe and FLTLIB.dll to load JFMBackdoor, a full-featured espionage implant supporting reverse shell access, file and process management, service control, registry modification, screenshot capture, TCP proxying, encrypted configuration handling, self-removal, and anti-forensics. The content also states that Win.NOODLERAT Type 0x132A was used only by Calypso APT, suggesting an exclusive variant for this actor.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

7 of 15 tactics14 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1190
Exploit Public-Facing Application
TA0003
Persistence
1 technique
T1543
Create or Modify System Process
T1543.003
Windows Service
TA0004
Privilege Escalation
1 technique
T1543
Create or Modify System Process
T1543.003
Windows Service
TA0005
Stealth
2 techniques
T1036
Masquerading
T1564
Hide Artifacts
TA0007
Discovery
1 technique
T1082
System Information Discovery
TA0008
Lateral Movement
1 technique
T1021
Remote Services
TA0011
Command and Control
4 techniques
T1071
Application Layer Protocol
T1090
Proxy
T1102
Web Service
T1102.001
Dead Drop Resolver
T1105
Ingress Tool Transfer
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping10

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal3

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs4

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.