Cinnamon Tempest
Also reported as DEV-0401, Emperor Dragonfly, BRONZE STARLIGHT, SLIME34, HighGround and 2 other names. Linked to China by four sources.
Reports per quarter
Techniques seen in the last two years
- T1016 1 report reports only
- T1021.001 1 report reports only
- T1027.002 1 report reports only
- T1039 1 report reports only
- T1047 1 report in ATT&CK
- T1048 1 report reports only
- T1056.001 1 report reports only
- T1059.001 1 report in ATT&CK
- T1059.003 1 report in ATT&CK
- T1070.004 1 report reports only
Show all 25 techniques Show fewer
- T1071.001 1 report reports only
- T1082 1 report reports only
- T1087.002 1 report reports only
- T1090 1 report in ATT&CK
- T1095 1 report reports only
- T1132.001 1 report reports only
- T1135 1 report reports only
- T1190 1 report in ATT&CK
- T1486 1 report reports only
- T1543.003 1 report in ATT&CK
- T1567.002 1 report in ATT&CK
- T1569.002 1 report reports only
- T1570 1 report reports only
- T1572 1 report in ATT&CK
- T1573 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2018-13379 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-14882 KEV
- CVE-2020-8243 KEV
- CVE-2020-8260 KEV
- CVE-2021-1879 KEV
- CVE-2021-20016 KEV ransomware
- CVE-2021-21166 KEV
- CVE-2021-21974
Show all 48 CVEs Show fewer
- CVE-2021-22893 KEV ransomware
- CVE-2021-22894 KEV
- CVE-2021-22899 KEV
- CVE-2021-22900 KEV
- CVE-2021-25748
- CVE-2021-26084 KEV ransomware
- CVE-2021-26868
- CVE-2021-30551 KEV
- CVE-2021-31207 KEV ransomware
- CVE-2021-33742 KEV
- CVE-2021-34473 KEV ransomware
- CVE-2021-35247 KEV
- CVE-2021-36942 KEV ransomware
- CVE-2021-38001
- CVE-2021-40444 KEV ransomware
- CVE-2021-40539 KEV ransomware
- CVE-2021-44228 KEV ransomware
- CVE-2021-4428
- CVE-2021-44428
- CVE-2021-44832
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-26134 KEV ransomware
- CVE-2022-27924 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2023-23397 KEV
- CVE-2023-27350 KEV ransomware
- CVE-2023-34362 KEV ransomware
- CVE-2023-5631 KEV
- CVE-2024-0012 KEV ransomware
- CVE-2024-1708 KEV ransomware
- CVE-2024-1709 KEV ransomware
- CVE-2024-21413 KEV
- CVE-2024-30051 KEV ransomware
- CVE-2026-1731 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor HelloKitty (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor WastedLocker (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Griffon (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor PlugX (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor DarkSide (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor FiveHands (Malware Family)
Show all 35 reports Show fewer
-
Cobalt Strike (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Cobalt Strike (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Quasar RAT (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Maze (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor BlackMatter (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor LockBit (Malware Family)
-
BRONZE STARLIGHT Ransomware Operations Use HUI Loader
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BRONZE STARLIGHT Ransomware Operations Use HUI Loader
-
Ransomware-as-a-service- Understanding the cybercrime gig economy and how to protect yourself
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransomware-as-a-service- Understanding the cybercrime gig economy and how to protect yourself
-
LockBit Ransomware Side-loads Cobalt Strike Beacon with Legitimate VMware Utility
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor LockBit Ransomware Side-loads Cobalt Strike Beacon with Legitimate VMware Utility
-
Threat Advisory- VMware Horizon Servers Actively Being Hit With Cobalt Strike (by DEV-0401)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Advisory- VMware Horizon Servers Actively Being Hit With Cobalt Strike (by DEV-0401)
-
Guidance for preventing, detecting, and hunting for exploitation of the Log4j 2 vulnerability
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Guidance for preventing, detecting, and hunting for exploitation of the Log4j 2 vulnerability
-
CSET - Academics, AI, and APTs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CSET - Academics, AI, and APTs
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Mandiant_APT1_Report
Newest first. Details opens the report in Explore.