Velvet Tempest is a BlackCat-affiliated threat actor known for multi-sector targeting, Cobalt Strike, and data exfiltration.
Analyst brief
Velvet Tempest is a threat actor associated with the BlackCat ransomware group. They target industries such as energy, fashion, tobacco, IT, and manufacturing. Their TTPs include using access brokers for initial entry, deploying Cobalt Strike Beacons and PsExec for lateral movement and staging, and exfiltrating data with the StealBit tool. Defenders should focus on detecting attempts to disable unprotected antivirus products, Cobalt Strike indicators, and unauthorized lateral movement activities.
Velvet Tempest
DEV-0504ALPHA SPIDER
unknown
Velvet Tempest is a threat actor associated with the BlackCat ransomware group. They have been observed deploying multiple ransomware payloads, including BlackCat, and have targeted various industries such as energy, fashion, tobacco, IT, and manufacturing. Velvet Tempest relies on access brokers to gain network access and utilizes tools like Cobalt Strike Beacons and PsExec for lateral movement and payload staging. They exfiltrate stolen data using a tool called StealBit and frequently disable unprotected antivirus products.