calipology is a financially motivated cybercrime actor associated with the Striker/GeorgeGinx operator cluster and linked to distribution of trojanized software installers that deploy a weaponized RustDesk remote access payload. The actor has been tied to infrastructure overlap with earlier Striker command-and-control activity and appears to have evolved from operating C2 infrastructure into signed malware distribution. Observed tradecraft includes use of trojanized legitimate software themes for initial access, remote access tooling for post-compromise control, and code-signing abuse to improve payload trust and reduce user suspicion. The actor has also been associated with exposed infrastructure hosting multiple administrative and web services, indicating broader criminal operations beyond a single malware delivery chain. Reporting further links the actor to a Telegram handle of the same name and to infrastructure that redirected to a legitimate UK brake caliper refurbishment business, suggesting possible use of a real-world business identity or cover. High-confidence reporting supports cybercriminal rather than state-sponsored activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.