Mustard Tempest is a threat actor known for malvertising and fake browser update lures leading to Cobalt Strike and ransomware deployment.
Analyst brief
Mustard Tempest (linked to EvilCorp) is a threat actor that primarily uses malvertising and fake browser update lures (SocGholish/FakeUpdates) to gain initial access. Once inside a network, it profiles the environment and downloads Cobalt Strike beacons, ultimately leading to ransomware deployment (e.g., WastedLocker, PhoenixLocker). Defenders should focus on user training against suspicious browser update prompts, strictly control JavaScript and ZIP execution, and monitor network traffic for Cobalt Strike C2 patterns.
Mustard Tempest
DEV-0206Purple VallhundTA569
unknown
Mustard Tempest is a threat actor that primarily uses malvertising as their main technique to gain access to and profile networks. They deploy FakeUpdates, disguised as browser updates or software packages, to lure targets into downloading a ZIP file containing a JavaScript file. Once executed, the JavaScript framework acts as a loader for other malware campaigns, often Cobalt Strike payloads. Mustard Tempest has been associated with the cybercrime syndicate Mustard Tempest, also known as EvilCorp, and has been involved in ransomware attacks using payloads such as WastedLocker, PhoenixLocker, and Macaw.