Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Calypso

Also known as: BRONZE MEDLEY, Red Lamassu, Links to Skyipot, Pitty Tiger, Comment Crew, Mirage, Crawling Taurus, TH3Bug, Charcoal Typhoon, CHROMIUM, VIOLIN PANDA1, malicious actors, APT groups, APT27, Emissary Panda, BARIUM, back.rooter.tk, cybersecurity, CVE-2021-27065, TG-2633, Winnti Umbrella, BRONZE ATLAS, tracked as, hackers, Bronze Butler, Soldier, APT41, Korplug, CactusPete, Vicious Panda

Description

Calypso focuses on long‑term espionage of state institutions, telecom operators, and critical infrastructure. Their initial approach relies on publicly disclosed Microsoft Exchange vulnerabilities (CVE‑2021‑26855/57/58/27065) to gain foothold without valid credentials, installing ASPX web shells in Exchange’s ASP.NET directories. Exploiting DLL search‑order hijacking and legitimate Windows executables, the actor drops powerful backdoors such as PlugX/Korplug and Shadowpad for persistence and command & control. Complementing its Windows tactics, Calypso deploys the Linux‑based Showboat malware on telecom network nodes, providing a SOCKS5 proxy to tunnel anonymised traffic and exfiltrate data. The toolkit also incorporates legacy exploits (EternalBlue/EternalRomance) and living‑off‑the‑land utilities, coupled with custom PowerShell loaders that move data via BITS or HTTPS streams. The group demonstrates supply‑chain capabilities by modifying a Pakistani government MSI installer to sideload malicious mscoree.dll, launching Shadowpad from the compromised system. Calypso’s operations are consistently coordinated: they strike before patch releases, maintain webshells until detection, and employ advanced evasion such as anti‑sandbox checks, dynamic code obfuscation, and encrypted in‑memory configuration states.

Goals & Targeting

Targeted Sectors

Government
Telecommunications
Financial services
Defense
Critical infrastructure
Information technology
Construction
Manufacturing
Mining
Aviation
Healthcare
Education
Aerospace
Technology
Media
Gaming

Targeted Countries / Regions

US
CN
PK
IN
RU
DE
JP
IT
KZ
AU
GB
UA
TR
BR
KR
SG

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 hours ago

Executive Summary

Calypso is a highly sophisticated espionage threat actor that primarily exploits Microsoft Exchange vulnerabilities to gain persistent access to government, telecom, and critical‑infrastructure targets across the globe. Leveraging ProxyLogon zero‑day CVEs it deploys a suite of RATs—including PlugX/Korplug, Shadowpad, Showboat, and custom backdoors—often via DLL search‑order hijacking or supply‑chain sideloading. The group actively maintains long‑term espionage campaigns using stealth C2 domains, keylogging droppers, and advanced anti‑sandbox obfuscation techniques.

Goals & Targeting

Calypso’s strategic objective is to acquire long‑term intelligence from high‑value targets in the public sector and critical infrastructure. It selects victims across North America, Europe, Asia, and Oceania, focusing on government agencies, defense contractors, telecom operators, financial services, and industrial sectors. The actor's targeting appears opportunistic but deliberate: initial infection vectors exploit unpatched Exchange servers, subsequently leveraging lateral movement for deeper access into secure networks.

Enhanced Description

Key Capabilities

  • Exploitation of Microsoft Exchange CVEs (CVE‑2021‑26855, 27065), including ProxyLogon
  • Deployment of ASPX web shells on compromised Exchange servers
  • DLL search‑order hijacking to drop Windows backdoors (PlugX/Korplug, Shadowpad)
  • Supply‑chain sideloading via malicious MSI installers (mscoree.dll)
  • Installation of Linux Showboat malware for SOCKS5 proxy and exfiltration
  • Use of legacy exploits (EternalBlue/EternalRomance) and living‑off‑the‑land utilities
  • Custom PowerShell loaders using BITS or HTTPS for data movement
  • Keylogging dropper components
  • Stealth C2 channels via malicious domains (live.musicweb.xyz, obovideocenter.org) and IPs
  • Advanced anti‑sandbox, dynamic code obfuscation, encrypted in‑memory config

ATT&CK Techniques

Persistence
1 technique
Reconnaissance
1 technique
Resource Development
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 3 Filename 3 Domain 9 SHA-1 Hash 4 SHA-256 Hash 1

References

Intel Summary

6

Techniques

60

Tools

0

Campaigns

40

IOCs

0

Observed Data

5

Tactics

Tags

APT
espionage
government-targeted
critical-infrastructure

Details

Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
C
Confidence
60%
Added
Jul 24, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.