NEW: Group Profiler — instant APT intel lookup. Try it →

Cinnamon Tempest

G1021 China MITRE ATT&CK →

Also known as: DEV-0401 · Emperor Dragonfly · BRONZE STARLIGHT

Overview

Cinnamon Tempest is a China-based threat group that has been active since at least 2021 deploying multiple strains of ransomware based on the leaked Babuk source code. Cinnamon Tempest does not operate their ransomware on an affiliate model or purchase access but appears to act independently in all stages of the attack lifecycle. Based on victimology, the short lifespan of each ransomware variant, and use of malware attributed to government-sponsored threat groups, Cinnamon Tempest may be motivated by intellectual property theft or cyberespionage rather than financial gain.

Naming & attribution

Cinnamon Tempest is tracked under 4 names across the industry. It uses 19 documented ATT&CK techniques — more than 51% of the 174 groups tracked here. Activity attributed since at least 2021.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
DEV-0401Microsoft
Emperor DragonflyBiderman, O. et al
BRONZE STARLIGHTSecureWorks

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Play — 9 shared techniques (25% overlap)
  • Blue Mockingbird — 8 shared techniques (24% overlap)
  • Aquatic Panda China — 9 shared techniques (20% overlap)
  • Earth Lusca China — 10 shared techniques (19% overlap)
  • GALLIUM China — 8 shared techniques (19% overlap)
  • INC Ransom — 7 shared techniques (19% overlap)

Malware families with current indicators

2 families attributed to Cinnamon Tempest, carrying 1,567 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • Sliver 1,562 indicators
  • Pandora 5 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1190
  • Custom malware/implant development — ATT&CK: 5 attributed custom malware families

TTPs — 19 techniques across 10 tactics

Resource Development

Initial Access

Execution

Persistence

Defense Impairment

Lateral Movement

Command and Control

Exfiltration

Impact

Tools & malware (8)

Sliver · Pandora · PlugX · Cheerscrypt · Impacket · Cobalt Strike · HUI Loader · Rclone

Reporting (3)