Also known as: BRONZE MEDLEY, Red Lamassu, Links to Skyipot, Pitty Tiger, Comment Crew, Mirage, Crawling Taurus, TH3Bug, Charcoal Typhoon, CHROMIUM, VIOLIN PANDA1, malicious actors, APT groups, APT27, Emissary Panda, BARIUM, back.rooter.tk, cybersecurity, CVE-2021-27065, TG-2633, Winnti Umbrella, BRONZE ATLAS, tracked as, hackers, Bronze Butler, Soldier, APT41, Korplug, CactusPete, Vicious Panda
Calypso focuses on long‑term espionage of state institutions, telecom operators, and critical infrastructure. Their initial approach relies on publicly disclosed Microsoft Exchange vulnerabilities (CVE‑2021‑26855/57/58/27065) to gain foothold without valid credentials, installing ASPX web shells in Exchange’s ASP.NET directories. Exploiting DLL search‑order hijacking and legitimate Windows executables, the actor drops powerful backdoors such as PlugX/Korplug and Shadowpad for persistence and command & control. Complementing its Windows tactics, Calypso deploys the Linux‑based Showboat malware on telecom network nodes, providing a SOCKS5 proxy to tunnel anonymised traffic and exfiltrate data. The toolkit also incorporates legacy exploits (EternalBlue/EternalRomance) and living‑off‑the‑land utilities, coupled with custom PowerShell loaders that move data via BITS or HTTPS streams. The group demonstrates supply‑chain capabilities by modifying a Pakistani government MSI installer to sideload malicious mscoree.dll, launching Shadowpad from the compromised system. Calypso’s operations are consistently coordinated: they strike before patch releases, maintain webshells until detection, and employ advanced evasion such as anti‑sandbox checks, dynamic code obfuscation, and encrypted in‑memory configuration states.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Calypso is a highly sophisticated espionage threat actor that primarily exploits Microsoft Exchange vulnerabilities to gain persistent access to government, telecom, and critical‑infrastructure targets across the globe. Leveraging ProxyLogon zero‑day CVEs it deploys a suite of RATs—including PlugX/Korplug, Shadowpad, Showboat, and custom backdoors—often via DLL search‑order hijacking or supply‑chain sideloading. The group actively maintains long‑term espionage campaigns using stealth C2 domains, keylogging droppers, and advanced anti‑sandbox obfuscation techniques.
Goals & Targeting
Calypso’s strategic objective is to acquire long‑term intelligence from high‑value targets in the public sector and critical infrastructure. It selects victims across North America, Europe, Asia, and Oceania, focusing on government agencies, defense contractors, telecom operators, financial services, and industrial sectors. The actor's targeting appears opportunistic but deliberate: initial infection vectors exploit unpatched Exchange servers, subsequently leveraging lateral movement for deeper access into secure networks.
Enhanced Description
Key Capabilities
No campaigns linked yet.
No observed data linked yet.
6
Techniques
60
Tools
0
Campaigns
40
IOCs
0
Observed Data
5
Tactics