Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: DEV-0401, Emperor Dragonfly, BRONZE STARLIGHT
19
techniques
8
software
10,840
corpus matches
profile
Cinnamon Tempest is a China-based threat group that has been active since at least 2021 deploying multiple strains of ransomware based on the leaked Babuk source code. Cinnamon Tempest does not operate their ransomware on an affiliate model or purchase access but appears to act independently in all stages of the attack lifecycle. Based on victimology, the short lifespan of each ransomware variant, and use of malware attributed to government-sponsored threat groups, Cinnamon Tempest may be motivated by intellectual property theft or cyberespionage rather than financial gain.
techniques
19 attributed · most-instrumented first
software
8 malware & tools attributed
PlugX
S0013
Cobalt Strike
S0154
Impacket
S0357
Sliver
S0633
Pandora
S0664
Rclone
S1040
Cheerscrypt
S1096
HUI Loader
S1097
read this carefully
10,840 corpus matches is not attribution
That count is indicators which exhibit techniques Cinnamon Tempest is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
+7 more techniques
showing 30 of 10,840
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.