Cinnamon Tempest — Ransomware Profile
Cinnamon Tempest - also tracked as Bronze Starlight, Emperor Dragonfly and DEV-0401 - is a China-based intrusion set that since mid-2021 has deployed a rapid succession of short-lived ransomware families built from leaked Babuk source code, including LockFile, AtomSilo, Rook, Night Sky, Pandora and Cheerscrypt, running every stage of its intrusions itself rather than buying access or operating an affiliate program. Its motivation is genuinely disputed between vendors: Secureworks assesses it as plausible that the group deploys ransomware as a smokescreen rather than for financial gain, with intellectual-property theft or espionage as the underlying goal, while Microsoft places it in its financially motivated Tempest family rather than the Typhoon family it reserves for Chinese nation-state actors, and Sygnia's incident responders describe it as a China-based ransomware operator that rebrands its payloads to stay under the radar. The China location is a moderate-confidence vendor assessment drawn from tradecraft - HUI Loader and PlugX use plus forked Chinese-language open-source tooling - and neither vendors nor any government have alleged state sponsorship. Symantec's February 2025 analysis of an RA World intrusion that reused a proxy tool previously seen in Bronze Starlight activity judged the likeliest explanation to be an operator monetising their employer's toolkit on the side rather than a state-directed cover operation.Also tracked as
DEV-0401, Emperor Dragonfly, BRONZE STARLIGHT, SLIME34, G1021
IntelFusions coverage (1)
- LockBit Affiliate Side-Loads Cobalt Strike via VMwareXferlogs.exe: Malicious glib-2.0.dll Bypasses EDR Hooks, ETW, and AMSI 2026-02-16 · Ransomware
Tools & malware
- Cheerscrypt Ransomware
- Cobalt Strike Adversary Simulation
- HUI Loader Loader
- Impacket Network Toolkit
- Pandora Ransomware
- PlugX Backdoor
- Rclone Exfiltration Tool
- Sliver Adversary Simulation
Vendor research
- BRONZE STARLIGHT SecureWorks
- How Microsoft names threat actors Microsoft
- BRONZE STARLIGHT RANSOMWARE OPERATIONS USE HUI LOADER Counter Threat Unit Research Team
- New Linux-Based Ransomware Cheerscrypt Targeting ESXi Devices Linked to Leaked Babuk Source Code Trend Micro
- REVEALING EMPEROR DRAGONFLY: NIGHT SKY AND CHEERSCRYPT - A SINGLE RANSOMWARE GROUP Sygnia
- BRONZE STARLIGHT RANSOMWARE OPERATIONS USE HUI LOADER Secureworks
- SecureWorks. (n.d.). BRONZE STARLIGHT Dell SecureWorks
- Ransomware as a service: Understanding the cybercrime gig economy and how to protect yourself Microsoft