# Calypso

> As of 2026-06-28, Calypso is a China-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning malware. Also known as BRONZE MEDLEY, Red Lamassu, Calypso APT. ATT&CK coverage spans 42 techniques across 10 tactics in 3 of 3 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1041 (Exfiltration Over C2 Channel), T1057 (Process Discovery).

- **Nation:** China
- **Tracked threats:** 3
- **Categories:** MALWARE
- **Also known as:** BRONZE MEDLEY, Red Lamassu, Calypso APT
- **As of:** 2026-06-28

## ATT&CK techniques observed

42 techniques observed across 3 of 3 tracked threats. Tactics: Command and Control (10), Stealth (formerly Defense Evasion) (9), Discovery (5), Resource Development (4), Collection (3), Execution (3).

- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 3 of 3 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 3 of 3 tracked threats
- [T1057](https://intel.threadlinqs.com/technique/T1057) Process Discovery — Discovery — observed in 3 of 3 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 3 of 3 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 3 of 3 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 3 of 3 tracked threats
- [T1113](https://intel.threadlinqs.com/technique/T1113) Screen Capture — Collection — observed in 3 of 3 tracked threats
- [T1573](https://intel.threadlinqs.com/technique/T1573) Encrypted Channel — Command and Control — observed in 3 of 3 tracked threats
- [T1574](https://intel.threadlinqs.com/technique/T1574) Hijack Execution Flow — Stealth (formerly Defense Evasion) — observed in 3 of 3 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 2 of 3 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1046](https://intel.threadlinqs.com/technique/T1046) Network Service Discovery — Discovery — observed in 2 of 3 tracked threats
- [T1083](https://intel.threadlinqs.com/technique/T1083) File and Directory Discovery — Discovery — observed in 2 of 3 tracked threats
- [T1090](https://intel.threadlinqs.com/technique/T1090) Proxy — Command and Control — observed in 2 of 3 tracked threats
- [T1102](https://intel.threadlinqs.com/technique/T1102) Web Service — Command and Control — observed in 2 of 3 tracked threats

## Tracked threats

- [Showboat: Sophisticated Linux Post-Exploitation Framework Targeting Middle East Telecommunications](https://intel.threadlinqs.com/threat/TL-2026-0990) — CRITICAL
- [Showboat (EvaRAT): PRC-Backed Modular Linux Post-Exploitation Framework Targeting Middle East Telecom Firms Since 2022](https://intel.threadlinqs.com/threat/TL-2026-0839) — HIGH
- [Calypso (Red Lamassu) China-Nexus Telco Espionage — Showboat Linux SOCKS5 Backdoor + JFMBackdoor Windows Implant](https://intel.threadlinqs.com/threat/TL-2026-0549) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Calypso
