Home > List all groups > List all tools > List all groups using tool Calypso RAT

Threat Group Cards: A Threat Actor Encyclopedia

Permanent link Tool: Calypso RAT

NamesCalypso RAT
Description(Positive Technologies) The dropper extracts the payload as an installation BAT script and CAB archive, and saves it to disk. The payload inside the dropper has a magic header that the dropper searches for.
The dropper encrypts and decrypts data with a self-developed algorithm that uses CRC32 as a pseudorandom number generator (PRNG). The algorithm performs arithmetic (addition and subtraction) between the generated data and the data that needs to be encrypted or decrypted.
Now decrypted, the payload is saved to disk at %ALLUSERSPROFILE;\TMP_%d%d, where the last two numbers are replaced by random numbers returned by the rand() function. Depending on the configuration, the CAB archive contains one of three possibilities: a DLL and encrypted shellcode, a DLL with encoded loader in the resources, or an EXE file. We were unable to detect any instances of the last variant.

Last change to this tool card: 19 April 2020

Download this tool card in JSON format

Previous: CallMe
Next: CamCapture Plugin

All groups using tool Calypso RAT


APT groups

 CalypsoChina2016-Mar 2021 

1 group listed (1 APT, 0 other, 0 unknown)

Thailand Computer Emergency Response Team (ThaiCERT)
Electronic Transactions Development Agency

Follow us on

Facebook Twitter

Report incidents

Telephone +66 (0)2-123-1234
PGP Download PGP key