Calypso is a China-linked cyber-espionage threat actor also tracked as Red Lamassu. The group has been observed targeting governmental entities and private-sector organizations across the Middle East, South America, Africa, Asia, and Europe, with a particular focus in later reporting on telecommunications providers in the Asia-Pacific region and parts of the Middle East. Calypso was among the multiple Chinese threat groups documented exploiting the Microsoft Exchange ProxyLogon vulnerabilities in early 2021, including activity assessed to have occurred while the flaws were still zero-days. In those Exchange intrusions, the group compromised email servers, deployed web shells and backdoors, and used credential-dumping tooling including Mimikatz for follow-on access. Calypso has been associated with several malware families and bespoke tooling. Reporting links the actor to a Calypso-specific dropper, the Trojan.Misics.1 malware family, and an exclusive Win.NOODLERAT variant identified as Type 0x132A. That NOODLERAT variant supports a full backdoor feature set, including file transfer, recursive directory listing, proxying, module execution, and self-deletion, and has been assessed as unique to Calypso rather than broadly shared across multiple clusters. More recent operations attributed to Red Lamassu/Calypso used Showboat, a modular Linux post-exploitation framework designed for persistence, host reconnaissance, file transfer, process hiding, SOCKS5 proxying, and port forwarding, as well as JFMBackdoor, a Windows espionage implant delivered through a DLL sideloading chain. JFMBackdoor supports reverse shell access, file and process management, registry modification, screenshot capture, TCP proxying, encrypted configuration handling, self-removal, and anti-forensics. Operationally, Calypso demonstrates tradecraft consistent with long-term espionage campaigns: exploitation of internet-facing enterprise infrastructure, deployment of web shells and backdoors, credential theft, persistence, internal pivoting, and data access within victim environments. The actor’s tooling and victimology align with broader Chinese state-linked intrusion activity, and available reporting consistently places Calypso among China-aligned espionage operators rather than financially motivated ransomware actors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
DevCore researchers made considerable progress that ultimately led to the discovery of a pre-authentication proxy vulnerability on Dec. 10, 2020. This vulnerability was given the name ProxyLogon by DevCore and is now known publicly as CVE-2021-26855.
On Dec. 30, 2020, DevCore also discovered a second post-authentication file write bug that could be chained together with the first vulnerability to gain privileged access to Exchange Servers and write files of an attacker’s choosing to any directory. This second vulnerability is now known publicly as CVE-2021-27065.
Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065
Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese cyber-espionage campaign targeting telecommunications providers across Asia Pacific and parts of the Middle East using newly discovered Linux and Windows malware for long-term persistence, espionage, proxying, and internal network pivoting.
Listed as one of the China-linked groups that followed early exploitation in the 2021 Microsoft Exchange vulnerability campaign.
Referenced as a China-linked threat group observed exploiting zero-day vulnerabilities in Microsoft Exchange (2021).
Used the full-featured Win.NOODLERAT Type 0x132A, likely as an exclusive version.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.