A financially motivated threat actor from China since 2021, deploying ransomware globally.
Analyst brief
BRONZE STARLIGHT, also tracked as Cinnamon Tempest, is a financially motivated threat actor likely based in China, active since mid-2021. It targets a wide range of industries globally, deploying ransomware as part of name-and-shame schemes. The group exploits public-facing applications for initial access and leverages tools like HUI Loader, Cobalt Strike, PlugX, Sliver, and Impacket for lateral movement (SMB/Admin Shares), execution (WMI, Python), and data exfiltration to cloud storage. Defenders should monitor for abnormal SMB/WMI activity, Group Policy modifications on Domain Controllers, known loader anomalies, and treat ransomware events as potential smokescreens for broader intrusions.
BRONZE STARLIGHT
SLIME34DEV-0401Cinnamon Tempest
unknown
BRONZE STARLIGHT has been active since mid 2021 and targets organizations globally across a range of industry verticals. The group leverages HUI Loader to load Cobalt Strike and PlugX payloads for command and control. CTU researchers have observed BRONZE STARLIGHT deploying ransomware to compromised networks as part of name-and-shame ransomware schemes, and posted victim names to leak sites.
CTU researchers assess with moderate confidence that BRONZE STARLIGHT is located in China based on observed tradecraft, including the use of HUI Loader and PlugX which are associated with China-based threat group activity. It is plausible that BRONZE STARLIGHT deploys ransomware as a smokescreen rather than for financial gain, with the underlying motivation of stealing intellectual property theft or conducting espionage.
Monitor network traffic and system logs to detect suspicious SMB/Windows Admin Shares activity and tainted shared content, and restrict access to shared resources.
Monitor system logs and financial transactions to detect suspicious activity indicative of financial theft, and restrict access to sensitive transactions.
FAQ2
What methods does BRONZE STARLIGHT use for lateral movement?+
BRONZE STARLIGHT uses SMB/Admin Shares, WMI, and Python execution for lateral movement, along with tools such as Cobalt Strike, PlugX, Sliver, and Impacket.
What tactic of BRONZE STARLIGHT in ransomware operations should defenders pay special attention to?+
Defenders should treat ransomware events as potential smokescreens, as BRONZE STARLIGHT may use ransomware to mask broader intrusions.