Cinnamon Tempest — Ransomware Profile

Cinnamon Tempest - also tracked as Bronze Starlight, Emperor Dragonfly and DEV-0401 - is a China-based intrusion set that since mid-2021 has deployed a rapid succession of short-lived ransomware families built from leaked Babuk source code, including LockFile, AtomSilo, Rook, Night Sky, Pandora and Cheerscrypt, running every stage of its intrusions itself rather than buying access or operating an affiliate program. Its motivation is genuinely disputed between vendors: Secureworks assesses it as plausible that the group deploys ransomware as a smokescreen rather than for financial gain, with intellectual-property theft or espionage as the underlying goal, while Microsoft places it in its financially motivated Tempest family rather than the Typhoon family it reserves for Chinese nation-state actors, and Sygnia's incident responders describe it as a China-based ransomware operator that rebrands its payloads to stay under the radar. The China location is a moderate-confidence vendor assessment drawn from tradecraft - HUI Loader and PlugX use plus forked Chinese-language open-source tooling - and neither vendors nor any government have alleged state sponsorship. Symantec's February 2025 analysis of an RA World intrusion that reused a proxy tool previously seen in Bronze Starlight activity judged the likeliest explanation to be an operator monetising their employer's toolkit on the side rather than a state-directed cover operation.

Also tracked as

DEV-0401, Emperor Dragonfly, BRONZE STARLIGHT, SLIME34, G1021

IntelFusions coverage (1)

Tools & malware

Vendor research

Read the full analysis on IntelFusions