Mustard Tempest — Ransomware Profile
Mustard Tempest is an initial access broker that has operated the SocGholish distribution network since at least 2017. Mustard Tempest has partnered with Indrik Spider to provide access for the download of additional malware including LockBit, WastedLocker, and remote access tools.Also tracked as
DEV-0206, TA569, GOLD PRELUDE, UNC1543
Tools & malware
- Cobalt Strike Adversary Simulation
- SocGholish Downloader
Vendor research
- How Microsoft names threat actors Microsoft
- GOLD PRELUDE Secureworks
- SocGholish, a very real threat from a very fake update SocGholish
- Ransomware as a service: Understanding the cybercrime gig economy and how to protect yourself Microsoft
- Secureworks. (n.d.). GOLD PRELUDE Secureworks