Threat group.View on attack.mitre.org
Cinnamon Tempest is a China-based threat group that has been active since at least 2021 deploying multiple strains of ransomware based on the leaked Babuk source code. Cinnamon Tempest does not operate their ransomware on an affiliate model or purchase access but appears to act independently in all stages of the attack lifecycle. Based on victimology, the short lifespan of each ransomware variant, and use of malware attributed to government-sponsored threat groups, Cinnamon Tempest may be motivated by intellectual property theft or cyberespionage rather than financial gain.
| Technique | Procedure example |
|---|---|
| T1021.002 SMB/Windows Admin Shares |
Cinnamon Tempest has used SMBexec for lateral movement. |
| T1047 Windows Management Instrumentation |
Cinnamon Tempest has used Impacket for lateral movement via WMI. |
| T1059.001 PowerShell |
Cinnamon Tempest has used PowerShell to communicate with C2, download files, and execute reconnaissance commands. |
| T1059.003 Windows Command Shell |
Cinnamon Tempest has executed ransomware using batch scripts deployed via GPO. |
| T1059.006 Python |
Cinnamon Tempest has used a customized version of the Impacket wmiexec.py module to create renamed output files. |
| T1078 Valid Accounts |
Cinnamon Tempest has used compromised user accounts to deploy payloads and create system services. |
| T1078.002 Domain Accounts |
Cinnamon Tempest has obtained highly privileged credentials such as domain administrator in order to deploy malware. |
| T1080 Taint Shared Content |
Cinnamon Tempest has deployed ransomware from a batch file in a network share. |
| T1090 Proxy |
Cinnamon Tempest has used a customized version of the Iox port-forwarding and proxy tool. |
| T1105 Ingress Tool Transfer |
Cinnamon Tempest has downloaded files, including Cobalt Strike, to compromised hosts. |
| T1140 Deobfuscate/Decode Files or Information |
Cinnamon Tempest has used weaponized DLLs to load and decrypt payloads. |
| T1190 Exploit Public-Facing Application |
Cinnamon Tempest has exploited multiple unpatched vulnerabilities for initial access including vulnerabilities in Microsoft Exchange, Manage Engine AdSelfService Plus, Confluence, and Log4j. |
| T1484.001 Group Policy Modification |
Cinnamon Tempest has used Group Policy to deploy batch scripts for ransomware deployment. |
| T1543.003 Windows Service |
Cinnamon Tempest has created system services to establish persistence for deployed tooling. |
| T1567.002 Exfiltration to Cloud Storage |
Cinnamon Tempest has uploaded captured keystroke logs to the Alibaba Cloud Object Storage Service, Aliyun OSS. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.