Mustard Tempest
MITRE ATT&CK: G1020 View on attack.mitre.org
Aliases: DEV-0206, TA569, GOLD PRELUDE, UNC1543, Purple Vallhund, Mustard Tempest, INDRIK SPIDER
- First seen
- 2017-01-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- criminal
- Related IoCs
- 3 (2 malicious)
- Last IoC activity
- 2026-09-01 15:17:16
- Profile updated
- 2026-07-07 11:56:21
Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications retail-and-hospitality
Context
Mustard Tempest is an initial access broker that has operated the SocGholish distribution network since at least 2017. Mustard Tempest has partnered with Indrik Spider to provide access for the download of additional malware including LockBit, WastedLocker, and remote access tools.
Recent IoC activity
2 malicious indicators in Maltiverse are attributed to Mustard Tempest (G1020). The 2 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | pausewatchings.com | 2026-09-02 | 1 |
| hostname | nodeapiintegrate.com | 2026-05-07 | 2 |
Detection coverage
- 146 YARA rules
- 125 Sigma rules
Malware & tools used
- Malvertising (attack-pattern)
- Upload Malware (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Spearphishing Link (attack-pattern)
- Domains (attack-pattern)
- SEO Poisoning (attack-pattern)
- Drive-by Target (attack-pattern)
- Drive-by Compromise (attack-pattern)
- Malicious Link (attack-pattern)
- System Information Discovery (attack-pattern)
- Server (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- SocGholish (malware)
- Cobalt Strike (malware)
Related threat objects
- INDRIK SPIDER (threat-actor)
Reports & references
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- secureworks.com — Gold Prelude (report)
- Microsoft — Raspberry Robin Worm Part Of Larger Ecosystem Facilitating Pre Ransomware Activity (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)
- MITRE ATT&CK — G1020 (report)
- proofpoint.com — Part 1 Socgholish Very Real Threat Very Fake Update (report)