Threadlinqs IntelligenceStart free

Threat actorChinaTracked since 2026-05

Calypso

Also known as:BRONZE MEDLEYRed LamassuCalypso APT

As of 2026-06-28, Calypso is a China-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning malware. Also known as BRONZE MEDLEY, Red Lamassu, Calypso APT. ATT&CK coverage spans 42 techniques across 10 tactics in 3 of 3 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1041 (Exfiltration Over C2 Channel), T1057 (Process Discovery).

Tracked threats
31 critical · 2 high
First seen
2026-05-21
Last seen
2026-06-28
ATT&CK techniques
42across 3 of 3 threats
Related CVEs
0None referenced
Attribution
ChinaNation or origin
Nation: China · 3 tracked threat(s) · Categories: MALWARE

Activity timeline

Calypso appears in 3 tracked threats between and ; the busiest month was 2026-06 with 2 reports.

ATT&CK techniques observed

42 techniques observed across 3 of 3 tracked threats · Command and Control (10), Stealth (formerly Defense Evasion) (9), Discovery (5), Resource Development (4), Collection (3), Execution (3)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 3 of 3 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 3 of 3 tracked threats
  • T1057 Process Discovery — Discoveryobserved in 3 of 3 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 3 of 3 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 3 of 3 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 3 of 3 tracked threats
  • T1113 Screen Capture — Collectionobserved in 3 of 3 tracked threats
  • T1573 Encrypted Channel — Command and Controlobserved in 3 of 3 tracked threats
  • T1574 Hijack Execution Flow — Stealth (formerly Defense Evasion)observed in 3 of 3 tracked threats
  • T1005 Data from Local System — Collectionobserved in 2 of 3 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
  • T1046 Network Service Discovery — Discoveryobserved in 2 of 3 tracked threats
  • T1083 File and Directory Discovery — Discoveryobserved in 2 of 3 tracked threats
  • T1090 Proxy — Command and Controlobserved in 2 of 3 tracked threats
  • T1102 Web Service — Command and Controlobserved in 2 of 3 tracked threats

Tracked threats