Calypso__2019__calypso-apt-2019-rus.pdf
ID: 3210801c-bf15-40dc-a96d-c5faec77d1aa
STIX ID: report--3210801c-bf15-40dc-a96d-c5faec77d1aa
Threat Score
88/100
Uploaded: 2026-08-14
Published Date: 2019-10-23
Last Modified Date: 2019-10-23
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Positive Technologies technical analysis of the Calypso APT: an advanced actor active since at least 2016 targeting government organizations across multiple countries. The report details initial access via ASPX web shells, lateral movement (Mimikatz, MS17-010/EternalBlue/DoublePulsar), multiple custom payloads (Calypso RAT, stagers, droppers, Hussar, FlyingDutchman), module architecture and network protocol/RC4-based encryption, provides extensive IOCs (IPs, domains, hashes) and maps observed behaviors to MITRE ATT&CK.
