Mustard Tempest
Also known as: DEV-0206 · TA569 · GOLD PRELUDE · UNC1543
Overview
Mustard Tempest is an initial access broker that has operated the SocGholish distribution network since at least 2017. Mustard Tempest has partnered with Indrik Spider to provide access for the download of additional malware including LockBit, WastedLocker, and remote access tools.
Naming & attribution
Mustard Tempest is tracked under 5 names across the industry. It uses 12 documented ATT&CK techniques — more than 35% of the 174 groups tracked here. Activity attributed since at least 2017.
| Name | First reported by |
|---|---|
| DEV-0206 | Microsoft |
| TA569 | Secureworks |
| GOLD PRELUDE | Secureworks |
| UNC1543 | Secureworks |
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1583.008Malvertising — used by 1 of 174 groups -
T1608.006SEO Poisoning — used by 1 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Transparent Tribe Pakistan — 6 shared techniques (30% overlap)
- Elderwood China — 4 shared techniques (24% overlap)
- SideCopy Pakistan — 5 shared techniques (22% overlap)
- Machete — 4 shared techniques (21% overlap)
- Windshift — 5 shared techniques (19% overlap)
- LuminousMoth China — 6 shared techniques (18% overlap)
Malware families with current indicators
One family attributed to Mustard Tempest, carrying 152 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.
- SocGholish 152 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
TTPs — 12 techniques across 6 tactics
Resource Development
-
T1583.004Server -
T1583.008Malvertising -
T1584.001Domains -
T1608.001Upload Malware -
T1608.004Drive-by Target -
T1608.006SEO Poisoning
Initial Access
-
T1189Drive-by Compromise -
T1566.002Spearphishing Link
Execution
-
T1204.001Malicious Link
Stealth
Discovery
Command and Control
-
T1105Ingress Tool Transfer
Tools & malware (2)
SocGholish · Cobalt Strike