Also known as: DEV-0206, TA569, GOLD PRELUDE, UNC1543, Purple Vallhund
Mustard Tempest is an initial access broker that has operated the SocGholish distribution network since at least 2017. Mustard Tempest has partnered with Indrik Spider to provide access for the download of additional malware including LockBit, WastedLocker, and remote access tools.(Citation: Microsoft Ransomware as a Service)(Citation: Microsoft Threat Actor Naming July 2023)(Citation: Secureworks Gold Prelude Profile)(Citation: SocGholish-update)
Executive Summary
Mustard Tempest is an initial access broker known since at least 2017, operating the SocGholish malware distribution network. The group has collaborated with Indrik Spider to provide access to additional恶意软件如LockBit和WastedLocker. Their primary activities involve delivering ransomware and remote access tools through various campaigns.
Goals & Targeting
Mustard Tempest's strategic objectives appear to focus on maximizing financial gain through the distribution of恶意软件, particularly ransomware. They target victims across multiple sectors, likely selecting based on opportunities for successful infection and high revenue potential。Their broad targeting approach suggests they seek out vulnerable organizations regardless of industry, with a particular emphasis on entities that can be compromised through their chosen attack vectors such as SocGholish campaigns.
Enhanced Description
Mustard Tempest operates as an initial access broker, primarily known for running the SocGholish malware distribution network since at least 2017. The group has established partnerships with other cybercriminal entities, such as Indrik Spider, to expand their attack capabilities by offering access to additional恶意软件 like LockBit ransomware、WastedLocker和远程访问工具。Their activities are centered around providing infrastructure and tools for further attacks, making them a significant player in the cybercrime ecosystem. The group's operations involve multiple stages of infection, including spear-phishing、malvertising、and drive-by-compromise techniques to deliver their payloads. Their collaboration with other threat actors underscores their role as a facilitator in the ransomware-as-a-service (RaaS) model.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Mustard Tempest has been active since at least 2017, with campaigns involving SocGholish updates and partnerships with other ransomware operators. Their operational tempo appears steady, with continuous efforts to distribute malware through various channels such as malvertising、drive-by attacks、and phishing。Notable past operations include the distribution of LockBit and WastedLocker ransomware, targeting organizations globally across multiple industries。
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in Mustard Tempest's profile is high based on their known partnerships and historical activity. However, gaps exist in understanding the full scope of their operations, including specific targeting criteria and the extent of their collaboration with other threat actors。Additional intelligence on their long-term goals、 geographic targeting、and具体的attack patterns would enhance this assessment.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
12
Techniques
3
Tools
0
Campaigns
0
IOCs
0
Observed Data
6
Tactics