Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Velvet Tempest

Also known as: DEV-0504, ALPHA SPIDER, ALPHV Ransomware Group

Description

Velvet Tempest is a threat actor associated with the BlackCat ransomware group. They have been observed deploying multiple ransomware payloads, including BlackCat, and have targeted various industries such as energy, fashion, tobacco, IT, and manufacturing. Velvet Tempest relies on access brokers to gain network access and utilizes tools like Cobalt Strike Beacons and PsExec for lateral movement and payload staging. They exfiltrate stolen data using a tool called StealBit and frequently disable unprotected antivirus products.

AI Analysis

· 1 week ago

Executive Summary

Velvet Tempest is a sophisticated cyber threat actor linked to the BlackCat ransomware group known for deploying multiple ransomware payloads across various industries including energy, fashion, tobacco, IT, and manufacturing. They utilize Cobalt Strike Beacons for C2 communication and rely on access brokers to gain initial network access. Their operations involve disabling antivirus products, stealing sensitive data using StealBit, and encrypting systems for ransom demands.

Goals & Targeting

Velvet Tempest's primary goal appears to be financial gain through ransomware deployment and data theft for extortion purposes. They target sectors that are likely to pay ransoms and have higher concentrations of sensitive data, such as energy companies with critical infrastructure and manufacturing firms with valuable intellectual property. The group's targeting profile suggests a focus on industries where operational disruption could lead to significant financial loss or reputational damage. Their victims typically include organizations with weaker cybersecurity defenses, which they exploit through access brokers and internal network propagation.

Enhanced Description

Velvet Tempest is a prominent threat actor associated with the BlackCat ransomware group, which has been active since at least 2021. The group primarily targets organizations across various industries, including energy, fashion, tobacco, IT, and manufacturing, often focusing on high-value sectors with deep operational knowledge. Velvet Tempest operates with financial motivations, seeking to extort ransoms from their victims while also exfiltrating sensitive data for potential secondary extortion or sale on the dark web. Their operations are characterized by a reliance on access brokers to obtain initial network access, use of tools like Cobalt Strike Beacons for command and control communication, and deployment of PsExec for lateral movement. The group also employs StealBit, a custom tool designed for data exfiltration, and frequently disables antivirus products to avoid detection and disrupt victim defenses. Velvet Tempest's strategic approach includes targeting organizations with weaker cybersecurity measures, leveraging their tools and techniques to remain undetected until the ransomware payload is deployed.

Key Capabilities

  • Deployment of multiple ransomware payloads, including BlackCat
  • Use of Cobalt Strike Beacons for C2 communication
  • Lateral movement via PsExec and Task Scheduler manipulation
  • Data exfiltration using StealBit tool
  • Disabling antivirus products to avoid detection
  • Spear-phishing campaigns with macro-laced Office documents as a potential initial attack vector

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Defense Evasion
Discovery
Lateral Movement

ATT&CK Techniques

T1059.003 - Command and Control via C2 Beaconing (Cobalt Strike Beacons)
T1685.001 - Use of Legitimate Remote Tools (PsExec for Lateral Movement)
T1048 - Data Transfer Through Encrypted Channels (Exfiltration using StealBit)
T1566.001 - Exfil Data via Encrypted Files (Ransomware encryption)

Software / Tooling

Cobalt Strike Beacon
PsExec
Task Scheduler (for persistence)
StealBit (custom data exfiltration tool)
Macro-laced Office documents (spear-phishing)

Campaigns & Victims

Velvet Tempest has been observed in multiple campaigns targeting various industries. Their operations often involve a slow-burn phase, where they establish persistence and lateral movement within the network before deploying ransomware or exfiltrating data. Notable campaign patterns include the use of access brokers for initial entry, disabling of antivirus products during attacks, and selection of victims based on perceived ability to pay ransoms. Their operational tempo suggests a well-organized group with clear internal processes for planning, execution, and post-attack communication.

IOC Patterns

  • C2 beaconing via Cobalt Strike-like tools
  • Process creation related to PsExec or Task Scheduler
  • Use of encrypted communication channels for data exfiltration
  • Spear-phishing emails with macro-laced Office documents
  • Encrypted files appended with .ALPHV or similar ransomware extensions
  • Disabling or uninstalling antivirus products during active campaigns

Recommended Actions

  • Implement endpoint detection and response (EDR) solutions to detect Cobalt Strike beaconing and unusual process activity.
  • Monitor network traffic for signs of lateral movement tools like PsExec and Task Scheduler manipulation.
  • Conduct regular training sessions on phishing awareness to mitigate macro-based spear-phishing attacks.
  • Ensure antivirus products are resilient against process injection or deletion attempts by threat actors.
  • Apply strict access controls and monitor internal networks for unauthorized use of remote administrative tools.

Suggested Tags

Ransomware
APT
Cyber Espionage
Finance
Manufacturing
Energy

Confidence Assessment

High confidence in the threat actor's capability and modus operandi, based on observed TTPs and toolset. However, limited visibility into their long-term strategic motivations or exact geographic origin introduces some uncertainty.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Data Exfiltration
APT
Cyber Espionage
Finance
Manufacturing
Energy

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.