Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Mustard Tempest

Also known as: DEV-0206, TA569, GOLD PRELUDE, UNC1543, Purple Vallhund

Description

Mustard Tempest is an initial access broker that has operated the SocGholish distribution network since at least 2017. Mustard Tempest has partnered with Indrik Spider to provide access for the download of additional malware including LockBit, WastedLocker, and remote access tools.(Citation: Microsoft Ransomware as a Service)(Citation: Microsoft Threat Actor Naming July 2023)(Citation: Secureworks Gold Prelude Profile)(Citation: SocGholish-update)

AI Analysis

· 1 week ago

Executive Summary

Mustard Tempest is an initial access broker known since at least 2017, operating the SocGholish malware distribution network. The group has collaborated with Indrik Spider to provide access to additional恶意软件如LockBit和WastedLocker. Their primary activities involve delivering ransomware and remote access tools through various campaigns.

Goals & Targeting

Mustard Tempest's strategic objectives appear to focus on maximizing financial gain through the distribution of恶意软件, particularly ransomware. They target victims across multiple sectors, likely selecting based on opportunities for successful infection and high revenue potential。Their broad targeting approach suggests they seek out vulnerable organizations regardless of industry, with a particular emphasis on entities that can be compromised through their chosen attack vectors such as SocGholish campaigns.

Enhanced Description

Mustard Tempest operates as an initial access broker, primarily known for running the SocGholish malware distribution network since at least 2017. The group has established partnerships with other cybercriminal entities, such as Indrik Spider, to expand their attack capabilities by offering access to additional恶意软件 like LockBit ransomware、WastedLocker和远程访问工具。Their activities are centered around providing infrastructure and tools for further attacks, making them a significant player in the cybercrime ecosystem. The group's operations involve multiple stages of infection, including spear-phishing、malvertising、and drive-by-compromise techniques to deliver their payloads. Their collaboration with other threat actors underscores their role as a facilitator in the ransomware-as-a-service (RaaS) model.

Key Capabilities

  • SocGholish malware distribution
  • Collaboration with Indrik Spider
  • Ransomware deployment (LockBit、WastedLocker)
  • Malvertising and drive-by attacks
  • Initial access brokering

MITRE ATT&CK Tactics

Initial Access
Persistence
Exfiltration
Defense Evasion

ATT&CK Techniques

T1584.001
T1036.005
T1566.002
T1583.004
T1204.001
T1583.008
T1608.004
T1082
T1608.001
T1608.006
T1189
T1105

Software / Tooling

SocGholish
Cobalt Strike
LockBit
WastedLocker
Custom RAT

Campaigns & Victims

Mustard Tempest has been active since at least 2017, with campaigns involving SocGholish updates and partnerships with other ransomware operators. Their operational tempo appears steady, with continuous efforts to distribute malware through various channels such as malvertising、drive-by attacks、and phishing。Notable past operations include the distribution of LockBit and WastedLocker ransomware, targeting organizations globally across multiple industries。

IOC Patterns

  • Spear-phishing emails with malicious links
  • Malicious domains associated with SocGholish campaigns
  • Drive-by compromise through compromised websites
  • Malvertising campaigns redirecting to exploit sites
  • Delivery of Cobalt Strike payloads for post-exploitation

Recommended Actions

  • Monitor formalicious links and domains linked to Mustard Tempest campaigns.
  • Implement anti-malware tools to detect SocGholish-related activity.
  • Enhance email filtering to block phishing attempts with malicious links.
  • Conduct regular vulnerability assessments to mitigate drive-by attack risks.
  • Train employees to recognize spear-phishing attempts and malicious content.

Suggested Tags

Initial Access Broker
Ransomware
SocGholish
Malvertising
Drive-by Attack

Confidence Assessment

The confidence in Mustard Tempest's profile is high based on their known partnerships and historical activity. However, gaps exist in understanding the full scope of their operations, including specific targeting criteria and the extent of their collaboration with other threat actors。Additional intelligence on their long-term goals、 geographic targeting、and具体的attack patterns would enhance this assessment.

ATT&CK Techniques

Resource Development
6 techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. SocGholish-update — Andrew Northern. (2022, November 22). SocGholish, a very real threat from a very fake update. Retrieved February 13, 2024.
  2. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  3. Microsoft Ransomware as a Service — Microsoft. (2022, May 9). Ransomware as a service: Understanding the cybercrime gig economy and how to protect yourself. Retrieved March 10, 2023.
  4. Secureworks Gold Prelude Profile — Secureworks. (n.d.). GOLD PRELUDE . Retrieved March 22, 2024.

Intel Summary

12

Techniques

3

Tools

0

Campaigns

0

IOCs

0

Observed Data

6

Tactics

Tags

Ransomware
Initial Access Broker
SocGholish
Malvertising
Drive-by Attack

Details

MITRE ID
G1020
Type
Unknown
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--0d4ac089-ced4-4cc4-a989-174d08e6d030
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.