ATT&CKGroupsMustard Tempest

Mustard Tempest

G1020

Threat group.View on attack.mitre.org

About this group

Mustard Tempest is an initial access broker that has operated the SocGholish distribution network since at least 2017. Mustard Tempest has partnered with Indrik Spider to provide access for the download of additional malware including LockBit, WastedLocker, and remote access tools.

Techniques used12

Procedure examples12

TechniqueProcedure example
T1036.005
Match Legitimate Resource Name or Location

Mustard Tempest has used the filename `AutoUpdater.js` to mimic legitimate update files and has also used the Cyrillic homoglyph characters С `(0xd0a1)` and а `(0xd0b0)`, to produce the filename `Сhrome.Updаte.zip`.

T1082
System Information Discovery

Mustard Tempest has used implants to perform system reconnaissance on targeted systems.

T1105
Ingress Tool Transfer

Mustard Tempest has deployed secondary payloads and third stage implants to compromised hosts.

T1189
Drive-by Compromise

Mustard Tempest has used drive-by downloads for initial infection, often using fake browser updates as a lure.

T1204.001
Malicious Link

Mustard Tempest has lured users into downloading malware through malicious links in fake advertisements and spearphishing emails.

T1566.002
Spearphishing Link

Mustard Tempest has sent victims emails containing links to compromised websites.

T1583.004
Server

Mustard Tempest has acquired servers to host second-stage payloads that remain active for a period of either days, weeks, or months.

T1583.008
Malvertising

Mustard Tempest has posted false advertisements including for software packages and browser updates in order to distribute malware.

T1584.001
Domains

Mustard Tempest operates a global network of compromised websites that redirect into a traffic distribution system (TDS) to select victims for a fake browser update page.

T1608.001
Upload Malware

Mustard Tempest has hosted payloads on acquired second-stage servers for periods of either days, weeks, or months.

T1608.004
Drive-by Target

Mustard Tempest has injected malicious JavaScript into compromised websites to infect victims via drive-by download.

T1608.006
SEO Poisoning

Mustard Tempest has poisoned search engine results to return fake software updates in order to distribute malware.

Software2

Campaigns0

None recorded.

References4

  1. Microsoft Ransomware as a Service Open source
    Microsoft. (2022, May 9). Ransomware as a service: Understanding the cybercrime gig economy and how to protect yourself. Retrieved March 10, 2023.
  2. Microsoft Threat Actor Naming July 2023 Open source
    Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  3. Secureworks Gold Prelude Profile Open source
    Secureworks. (n.d.). GOLD PRELUDE . Retrieved March 22, 2024.
  4. SocGholish-update Open source
    Andrew Northern. (2022, November 22). SocGholish, a very real threat from a very fake update. Retrieved February 13, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.