Calypso__2019__calypso-apt-2019-eng.pdf
ID: 7c473400-db3e-46a4-be29-736b82e1b5b8
STIX ID: report--7c473400-db3e-46a4-be29-736b82e1b5b8
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2019-10-28
Last Modified Date: 2019-10-28
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
# Calypso APT — Executive summary
Positive Technologies documents the Calypso APT (active since at least 2016) that targets government organizations across multiple countries using ASPX web‑shells for initial access, custom Calypso RATs (x86/x64 shellcode stagers, Hussar, FlyingDutchman), and well‑known lateral movement tools/exploits (Mimikatz, EternalBlue, DoublePulsar, DCSync). The report analyzes dropper and loader internals, module loading and C2 protocols (custom RC4/RC4-like/SSL schemes over HTTP(S)/TCP), lists commands/modules, and provides extensive IOCs (IPs, domains, and file hashes) and MITRE ATT&CK mappings.
