Calypso, also tracked as Red Lamassu, is a China-linked cyber-espionage threat actor. The group has been associated with exploitation of Microsoft Exchange ProxyLogon vulnerabilities in early 2021 and with later espionage operations against telecommunications providers across the Asia Pacific region and parts of the Middle East. Reporting places Calypso among multiple Chinese espionage groups that obtained or used Exchange exploit capability before public patch release, indicating access to zero-day exploitation during the ProxyLogon period. During the Exchange intrusions, Calypso compromised email servers belonging to governmental entities in the Middle East and South America and subsequently targeted additional government and private-sector organizations in Africa, Asia, and Europe. Follow-on activity included deployment of web shells and backdoors, credential theft using Mimikatz, and broader post-compromise operations consistent with espionage objectives. Calypso has also been linked to exclusive use of a fully featured Win.NOODLERAT variant identified as Type 0x132A, suggesting access to tooling not broadly shared across other clusters. In more recent operations attributed to Red Lamassu, the actor targeted telecommunications organizations using impersonation infrastructure and deployed bespoke malware families for Linux and Windows. The Linux framework, Showboat, is a modular post-exploitation platform used for persistence, host reconnaissance, file transfer, process hiding, SOCKS5 proxying, and port forwarding to support internal pivoting. The Windows implant, JFMBackdoor, is delivered through a DLL sideloading chain and supports reverse shell access, file operations, process and service control, registry modification, screenshot capture, TCP proxying, encrypted configuration handling, self-removal, and anti-forensics. Known aliases include Red Lamassu and Calypso APT. The actor’s observed tradecraft supports assessment as a long-term espionage operator focused on persistent access to communications and enterprise infrastructure, credential collection, internal movement, and covert exfiltration.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
CVE-2021-26855 (CVSS Score: 9.1/10) – Is a server-side request forgery (SSRF) vulnerability in Microsoft Exchange, which allows a threat actor to send an arbitrary HTTP request and authenticate as the Exchange server.
CVE-2021-27065 (CVSS 7.8) is a post-authentication arbitrary file write vulnerability in Exchange. If the threat actor first authenticates with the Exchange server they could then use this vulnerability to write a file to any path on the server.
CVE-2021-26857 (CVSS Score: 7.8/10) – Is an insecure deserialization vulnerability in the Unified Messaging service and requires administrator privileges or the use of another vulnerability to exploit. This vulnerability gave HAFNIUM the controls to run code as SYSTEM on an exchange server.
CVE-2021-26858 (CVSS 7.8) is a post-authentication arbitrary file write vulnerability in Exchange. If the threat actor first authenticates with the Exchange server they could then use this vulnerability to write a file to any path on the server.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
One of multiple espionage groups reported as exploiting at least one of the Microsoft Exchange vulnerabilities.
Chinese cyber-espionage campaign targeting telecommunications providers across Asia Pacific and parts of the Middle East using newly discovered Linux and Windows malware for long-term persistence, espionage, proxying, and internal network pivoting.
Listed as one of the China-linked groups that followed early exploitation in the 2021 Microsoft Exchange vulnerability campaign.
Referenced as a China-linked threat group observed exploiting zero-day vulnerabilities in Microsoft Exchange (2021).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.