Also known as: DEV-0504, ALPHA SPIDER, ALPHV Ransomware Group
Velvet Tempest is a threat actor associated with the BlackCat ransomware group. They have been observed deploying multiple ransomware payloads, including BlackCat, and have targeted various industries such as energy, fashion, tobacco, IT, and manufacturing. Velvet Tempest relies on access brokers to gain network access and utilizes tools like Cobalt Strike Beacons and PsExec for lateral movement and payload staging. They exfiltrate stolen data using a tool called StealBit and frequently disable unprotected antivirus products.
Executive Summary
Velvet Tempest is a sophisticated cyber threat actor linked to the BlackCat ransomware group known for deploying multiple ransomware payloads across various industries including energy, fashion, tobacco, IT, and manufacturing. They utilize Cobalt Strike Beacons for C2 communication and rely on access brokers to gain initial network access. Their operations involve disabling antivirus products, stealing sensitive data using StealBit, and encrypting systems for ransom demands.
Goals & Targeting
Velvet Tempest's primary goal appears to be financial gain through ransomware deployment and data theft for extortion purposes. They target sectors that are likely to pay ransoms and have higher concentrations of sensitive data, such as energy companies with critical infrastructure and manufacturing firms with valuable intellectual property. The group's targeting profile suggests a focus on industries where operational disruption could lead to significant financial loss or reputational damage. Their victims typically include organizations with weaker cybersecurity defenses, which they exploit through access brokers and internal network propagation.
Enhanced Description
Velvet Tempest is a prominent threat actor associated with the BlackCat ransomware group, which has been active since at least 2021. The group primarily targets organizations across various industries, including energy, fashion, tobacco, IT, and manufacturing, often focusing on high-value sectors with deep operational knowledge. Velvet Tempest operates with financial motivations, seeking to extort ransoms from their victims while also exfiltrating sensitive data for potential secondary extortion or sale on the dark web. Their operations are characterized by a reliance on access brokers to obtain initial network access, use of tools like Cobalt Strike Beacons for command and control communication, and deployment of PsExec for lateral movement. The group also employs StealBit, a custom tool designed for data exfiltration, and frequently disables antivirus products to avoid detection and disrupt victim defenses. Velvet Tempest's strategic approach includes targeting organizations with weaker cybersecurity measures, leveraging their tools and techniques to remain undetected until the ransomware payload is deployed.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Velvet Tempest has been observed in multiple campaigns targeting various industries. Their operations often involve a slow-burn phase, where they establish persistence and lateral movement within the network before deploying ransomware or exfiltrating data. Notable campaign patterns include the use of access brokers for initial entry, disabling of antivirus products during attacks, and selection of victims based on perceived ability to pay ransoms. Their operational tempo suggests a well-organized group with clear internal processes for planning, execution, and post-attack communication.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the threat actor's capability and modus operandi, based on observed TTPs and toolset. However, limited visibility into their long-term strategic motivations or exact geographic origin introduces some uncertainty.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics