Threat group.View on attack.mitre.org
Mustard Tempest is an initial access broker that has operated the SocGholish distribution network since at least 2017. Mustard Tempest has partnered with Indrik Spider to provide access for the download of additional malware including LockBit, WastedLocker, and remote access tools.
| Technique | Procedure example |
|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
Mustard Tempest has used the filename `AutoUpdater.js` to mimic legitimate update files and has also used the Cyrillic homoglyph characters С `(0xd0a1)` and а `(0xd0b0)`, to produce the filename `Сhrome.Updаte.zip`. |
| T1082 System Information Discovery |
Mustard Tempest has used implants to perform system reconnaissance on targeted systems. |
| T1105 Ingress Tool Transfer |
Mustard Tempest has deployed secondary payloads and third stage implants to compromised hosts. |
| T1189 Drive-by Compromise |
Mustard Tempest has used drive-by downloads for initial infection, often using fake browser updates as a lure. |
| T1204.001 Malicious Link |
Mustard Tempest has lured users into downloading malware through malicious links in fake advertisements and spearphishing emails. |
| T1566.002 Spearphishing Link |
Mustard Tempest has sent victims emails containing links to compromised websites. |
| T1583.004 Server |
Mustard Tempest has acquired servers to host second-stage payloads that remain active for a period of either days, weeks, or months. |
| T1583.008 Malvertising |
Mustard Tempest has posted false advertisements including for software packages and browser updates in order to distribute malware. |
| T1584.001 Domains |
Mustard Tempest operates a global network of compromised websites that redirect into a traffic distribution system (TDS) to select victims for a fake browser update page. |
| T1608.001 Upload Malware |
Mustard Tempest has hosted payloads on acquired second-stage servers for periods of either days, weeks, or months. |
| T1608.004 Drive-by Target |
Mustard Tempest has injected malicious JavaScript into compromised websites to infect victims via drive-by download. |
| T1608.006 SEO Poisoning |
Mustard Tempest has poisoned search engine results to return fake software updates in order to distribute malware. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.