Mustard Tempest — Ransomware Profile
Mustard Tempest is an initial access broker that has operated the SocGholish distribution network since at least 2017. Mustard Tempest has partnered with Indrik Spider to provide access for the download of additional malware including LockBit, WastedLocker, and remote access tools.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
DEV-0206, TA569, GOLD PRELUDE, UNC1543, Purple Vallhund
Tools & malware
- Cobalt Strike Adversary Simulation
- SocGholish Downloader
Vendor research
- GOLD PRELUDE Secureworks
- How Microsoft names threat actors Microsoft
- SocGholish, a very real threat from a very fake update SocGholish
- Ransomware as a service: Understanding the cybercrime gig economy and how to protect yourself Microsoft
- Secureworks. (n.d.). GOLD PRELUDE Secureworks