ATT&CKGroupsCinnamon Tempest

Cinnamon Tempest

G1021

Threat group.View on attack.mitre.org

About this group

Cinnamon Tempest is a China-based threat group that has been active since at least 2021 deploying multiple strains of ransomware based on the leaked Babuk source code. Cinnamon Tempest does not operate their ransomware on an affiliate model or purchase access but appears to act independently in all stages of the attack lifecycle. Based on victimology, the short lifespan of each ransomware variant, and use of malware attributed to government-sponsored threat groups, Cinnamon Tempest may be motivated by intellectual property theft or cyberespionage rather than financial gain.

Techniques used19

Procedure examples19

TechniqueProcedure example
T1021.002
SMB/Windows Admin Shares

Cinnamon Tempest has used SMBexec for lateral movement.

T1047
Windows Management Instrumentation

Cinnamon Tempest has used Impacket for lateral movement via WMI.

T1059.001
PowerShell

Cinnamon Tempest has used PowerShell to communicate with C2, download files, and execute reconnaissance commands.

T1059.003
Windows Command Shell

Cinnamon Tempest has executed ransomware using batch scripts deployed via GPO.

T1059.006
Python

Cinnamon Tempest has used a customized version of the Impacket wmiexec.py module to create renamed output files.

T1078
Valid Accounts

Cinnamon Tempest has used compromised user accounts to deploy payloads and create system services.

T1078.002
Domain Accounts

Cinnamon Tempest has obtained highly privileged credentials such as domain administrator in order to deploy malware.

T1080
Taint Shared Content

Cinnamon Tempest has deployed ransomware from a batch file in a network share.

T1090
Proxy

Cinnamon Tempest has used a customized version of the Iox port-forwarding and proxy tool.

T1105
Ingress Tool Transfer

Cinnamon Tempest has downloaded files, including Cobalt Strike, to compromised hosts.

T1140
Deobfuscate/Decode Files or Information

Cinnamon Tempest has used weaponized DLLs to load and decrypt payloads.

T1190
Exploit Public-Facing Application

Cinnamon Tempest has exploited multiple unpatched vulnerabilities for initial access including vulnerabilities in Microsoft Exchange, Manage Engine AdSelfService Plus, Confluence, and Log4j.

T1484.001
Group Policy Modification

Cinnamon Tempest has used Group Policy to deploy batch scripts for ransomware deployment.

T1543.003
Windows Service

Cinnamon Tempest has created system services to establish persistence for deployed tooling.

T1567.002
Exfiltration to Cloud Storage

Cinnamon Tempest has uploaded captured keystroke logs to the Alibaba Cloud Object Storage Service, Aliyun OSS.

View all 19 procedure examples

Software8

Campaigns0

None recorded.

References4

  1. Microsoft Ransomware as a Service Open source
    Microsoft. (2022, May 9). Ransomware as a service: Understanding the cybercrime gig economy and how to protect yourself. Retrieved March 10, 2023.
  2. Microsoft Threat Actor Naming July 2023 Open source
    Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  3. SecureWorks BRONZE STARLIGHT Ransomware Operations June 2022 Open source
    Counter Threat Unit Research Team . (2022, June 23). BRONZE STARLIGHT RANSOMWARE OPERATIONS USE HUI LOADER. Retrieved December 7, 2023.
  4. Trend Micro Cheerscrypt May 2022 Open source
    Dela Cruz, A. et al. (2022, May 25). New Linux-Based Ransomware Cheerscrypt Targeting ESXi Devices Linked to Leaked Babuk Source Code. Retrieved December 19, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.