Cinnamon Tempest — APT Profile
Cinnamon Tempest is a China-based threat group that has been active since at least 2021 deploying multiple strains of ransomware based on the leaked Babuk source code. Cinnamon Tempest does not operate their ransomware on an affiliate model or purchase access but appears to act independently in all stages of the attack lifecycle. Based on victimology, the short lifespan of each ransomware variant, and use of malware attributed to government-sponsored threat groups, Cinnamon Tempest may be motivated by intellectual property theft or cyberespionage rather than financial gain.Also tracked as
DEV-0401, Emperor Dragonfly, BRONZE STARLIGHT
Tools & malware
- Cheerscrypt Ransomware
- Cobalt Strike Adversary Simulation
- HUI Loader Loader
- Impacket Network Toolkit
- Pandora Ransomware
- PlugX Backdoor
- Rclone Exfiltration Tool
- Sliver Adversary Simulation
Vendor research
- BRONZE STARLIGHT SecureWorks
- BRONZE STARLIGHT RANSOMWARE OPERATIONS USE HUI LOADER Counter Threat Unit Research Team
- How Microsoft names threat actors Microsoft
- BRONZE STARLIGHT RANSOMWARE OPERATIONS USE HUI LOADER Secureworks
- REVEALING EMPEROR DRAGONFLY: NIGHT SKY AND CHEERSCRYPT - A SINGLE RANSOMWARE GROUP Sygnia
- SecureWorks. (n.d.). BRONZE STARLIGHT Dell SecureWorks
- New Linux-Based Ransomware Cheerscrypt Targeting ESXi Devices Linked to Leaked Babuk Source Code Trend Micro
- Ransomware as a service: Understanding the cybercrime gig economy and how to protect yourself Microsoft