Mustard Tempest

MITRE ATT&CK: G1020 View on attack.mitre.org

Aliases: DEV-0206, TA569, GOLD PRELUDE, UNC1543, Purple Vallhund, Mustard Tempest, INDRIK SPIDER

First seen
2017-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
advanced
Resource level
organization
Actor type
criminal
Related IoCs
3 (2 malicious)
Last IoC activity
2026-09-01 15:17:16
Profile updated
2026-07-07 11:56:21

Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications retail-and-hospitality

Context

Mustard Tempest is an initial access broker that has operated the SocGholish distribution network since at least 2017. Mustard Tempest has partnered with Indrik Spider to provide access for the download of additional malware including LockBit, WastedLocker, and remote access tools.

Recent IoC activity

2 malicious indicators in Maltiverse are attributed to Mustard Tempest (G1020). The 2 most recently updated:

TypeIndicatorUpdatedSources
hostname pausewatchings.com 2026-09-02 1
hostname nodeapiintegrate.com 2026-05-07 2

Detection coverage

  • 146 YARA rules
  • 125 Sigma rules

Malware & tools used

  • Malvertising (attack-pattern)
  • Upload Malware (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Domains (attack-pattern)
  • SEO Poisoning (attack-pattern)
  • Drive-by Target (attack-pattern)
  • Drive-by Compromise (attack-pattern)
  • Malicious Link (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Server (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • SocGholish (malware)
  • Cobalt Strike (malware)

Related threat objects

Reports & references

  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • secureworks.com — Gold Prelude (report)
  • Microsoft — Raspberry Robin Worm Part Of Larger Ecosystem Facilitating Pre Ransomware Activity (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)
  • MITRE ATT&CK — G1020 (report)
  • proofpoint.com — Part 1 Socgholish Very Real Threat Very Fake Update (report)

External references