Calypso is an APT group specializing in stealing confidential data from government agencies.
Analyst brief
The Calypso group (BRONZE MEDLEY, Red Lamassu) is a threat actor active since at least September 2016, focused on stealing confidential data. It primarily targets government agencies in Brazil, India, Kazakhstan, Russia, Thailand, and Turkey. Their activity involves numerous malware samples and identified C2 servers, though specific TTPs and tools are not detailed. Defenders should monitor for data exfiltration-focused APT activity targeting government sectors, watching for network anomalies and unauthorized data transfers.
Calypso
BRONZE MEDLEYRed Lamassu
unknown
For the first time, the activity of the Calypso group was detected by specialists of PT Expert Security Center in March 2019, during the work to detect cyber threats. As a result, many malware samples of this group were obtained, affected organizations and control servers of intruders were identified. According to our data, the group has been active since at least September 2016. The main goal of the group is to steal confidential data, the main victims are government agencies from Brazil, India, Kazakhstan, Russia, Thailand, Turkey. Our data suggest that the group has Asian roots. Description translated from Russian.