logo

Calypso__2019__calypso-apt-2019-rus.pdf

ID: 3210801c-bf15-40dc-a96d-c5faec77d1aa

STIX ID: report--3210801c-bf15-40dc-a96d-c5faec77d1aa

Threat Score

88/100

Uploaded: 2026-08-14

Published Date: 2019-10-23

Last Modified Date: 2019-10-23

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Positive Technologies technical analysis of the Calypso APT: an advanced actor active since at least 2016 targeting government organizations across multiple countries. The report details initial access via ASPX web shells, lateral movement (Mimikatz, MS17-010/EternalBlue/DoublePulsar), multiple custom payloads (Calypso RAT, stagers, droppers, Hussar, FlyingDutchman), module architecture and network protocol/RC4-based encryption, provides extensive IOCs (IPs, domains, hashes) and maps observed behaviors to MITRE ATT&CK.