calipology
calipology is a threat actor handle identified in reporting on a cybercrime campaign involving a trojanized Microsoft Teams installer (MSTeamsSetup.exe) that deploys a weaponized RustDesk remote access client. Breakglass Intelligence linked the actor to command-and-control infrastructure at mon.systemautoupdater[.]com and 23.27.141[.]44, and assessed this infrastructure overlap as confirmation that the previously identified GeorgeGinx/Striker operator expanded from Striker C2 framework operations into signed trojanized software distribution for financially motivated intrusion activity. The attribution is based on shared EvoXT hosting, a TLS certificate for calipology[.]com presented by 23.27.141[.]44, and overlap with the "calipology" Telegram attribution from the earlier Striker investigation. The infrastructure redirected HTTPS traffic to calipology[.]co[.]uk, described in the reporting as a legitimate UK brake caliper refurbishment business that may represent the operator’s real-world identity or cover. The malware sample was signed with a suspicious Certum-issued code-signing certificate for "Zlatin Stamatov," assessed in the report as likely stolen or fraudulently obtained. Investigators also observed multiple exposed services on the C2 server, including FTP, SSH, Apache, nginx, and a Python-hosted "Trading Bots Management" panel on port 3004, suggesting broader criminal activity beyond remote access malware distribution. Known associated aliases or linked designations directly mentioned in the content are GeorgeGinx and Striker.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they're from
Attributed origin per open-source reporting.
- GB
Tradecraft
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Observables
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.