Calypso, also known as Calypso APT and Red Lamassu, is a China-linked advanced persistent threat group conducting cyberespionage against government entities and private organizations. Its operations have targeted government email servers in the Middle East and South America, additional organizations across Africa, Asia, and Europe, and telecommunications providers in the Asia-Pacific region and parts of the Middle East. Calypso exploited Microsoft Exchange Server vulnerabilities associated with ProxyLogon before Microsoft's March 2021 patch release. These intrusions involved webshell deployment, a group-specific PlugX variant, the Whitebird backdoor, and Mimikatz for credential theft. The group loads backdoors through DLL search-order hijacking and sideloading using legitimate executables. It has also deployed the full-featured Type 0x132A variant of Win.NOODLERAT, which supports file transfer, recursive directory listing, module execution, TCP proxying, and self-deletion. Telecommunications espionage operations active since at least mid-2022 have used telecom-themed infrastructure to impersonate targeted organizations and deployed the Linux Showboat framework and Windows JFMBackdoor implant. Showboat supports service-based persistence, host reconnaissance, file transfer, process hiding, SOCKS5 proxying, and port forwarding to facilitate internal pivoting. JFMBackdoor is delivered through DLL sideloading and provides remote command execution, file and process management, service and registry manipulation, TCP proxying, screenshot capture and exfiltration, encrypted configuration handling, and anti-forensics. This combination of tools enables persistent access, information collection, and movement within compromised networks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
The report attributes initial intrusion to likely exploitation of CVE-2024-21893 and CVE-2024-21887. Files detected by Ivanti's Integrity Checker Tool matched filenames associated with LITTLELAMB, WOOLTEA, PITSOCK, and PITFUEL, and the observed evidence resembled previously reported attacks exploiting these vulnerabilities.
1 more CVE tied to this actor tracked in Mallory.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Identified as a group that has deployed Noodle RAT, a cross-platform remote-access trojan. The content does not specify Calypso's individual campaigns, victims, sponsorship or initial-access methods.
One of multiple espionage groups reported as exploiting at least one of the Microsoft Exchange vulnerabilities.
Chinese cyber-espionage campaign targeting telecommunications providers across Asia Pacific and parts of the Middle East using newly discovered Linux and Windows malware for long-term persistence, espionage, proxying, and internal network pivoting.
China-based group identified as a possible operator of the April 2025 campaign against Japanese shipping and transportation companies and their subsidiaries. Historical infrastructure overlaps suggest use of both MetaRAT and Talisman, but the campaign's C2 infrastructure does not establish definitive attribution. The report also cites Calypso's use of Talisman against a telecommunications operator in Kazakhstan. The Japanese campaign collected credentials, potentially to enable future re-entry; theft of confidential information was not observed.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.