Amethyst Rain
Microsoft threat actor profile. Origin/Threat: Lebanon.
Amethyst Rain is a Lebanon-based threat actor targeting telecommunications, media, and defense sectors in the Middle East.
Amethyst Rain (VolcanicTimber, Volatile Cedar) is a Lebanon-based threat actor. It primarily targets telecommunications, media, and defense sectors in the Middle East. The group uses open-source pentest tools (Mimikatz, PowerSploit), scans web applications, and collects data through remote access tools. Defenders should focus on patching web server vulnerabilities, monitoring PowerShell logs, and scrutinizing Remote Desktop Protocol (RDP) usage.
Microsoft threat actor profile. Origin/Threat: Lebanon.
Amethyst Rain primarily operates in the Middle East region.
Amethyst Rain uses open-source pentest tools such as Mimikatz and PowerSploit.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.