Cinnamon Tempest
MITRE ATT&CK: G1021 View on attack.mitre.org
Aliases: DEV-0401, Emperor Dragonfly, BRONZE STARLIGHT, SLIME34, Cinnamon Tempest, Bronze Starlight, HighGround
- First seen
- 2021-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Related IoCs
- 3 (3 malicious)
- Last IoC activity
- 2026-09-01 20:32:53
- Profile updated
- 2026-07-07 12:32:42
Targeted industries: government-and-public-sector technology-and-telecommunications healthcare-and-pharmaceutical financial-services
Targeted regions: country_code:us country_code:cn country_code:gb country_code:fr
Context
Cinnamon Tempest is a China-based threat group that has been active since at least 2021 deploying multiple strains of ransomware based on the leaked Babuk source code. Cinnamon Tempest does not operate their ransomware on an affiliate model or purchase access but appears to act independently in all stages of the attack lifecycle. Based on victimology, the short lifespan of each ransomware variant, and use of malware attributed to government-sponsored threat groups, Cinnamon Tempest may be motivated by intellectual property theft or cyberespionage rather than financial gain.
Recent IoC activity
3 malicious indicators in Maltiverse are attributed to Cinnamon Tempest (G1021). The 3 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | microsofts.com | 2026-09-03 | 1 |
| hostname | microupdate.xyz | 2026-07-28 | 2 |
| hostname | duckducklive.top | 2026-07-22 | 3 |
Detection coverage
- 165 YARA rules
- 673 Sigma rules
Malware & tools used
- DLL (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Group Policy Modification (attack-pattern)
- Exfiltration to Cloud Storage (attack-pattern)
- Tool (attack-pattern)
- Valid Accounts (attack-pattern)
- Financial Theft (attack-pattern)
- Proxy (attack-pattern)
- Domain Accounts (attack-pattern)
- Exploit Public-Facing Application (attack-pattern)
- Python (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- SMB/Windows Admin Shares (attack-pattern)
- Protocol Tunneling (attack-pattern)
- Taint Shared Content (attack-pattern)
- Windows Service (attack-pattern)
- PowerShell (attack-pattern)
- Windows Command Shell (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Sliver (malware)
- Impacket (malware)
- HUI Loader (malware)
- Rclone (malware)
- Cheerscrypt (malware)
- PlugX (malware)
Exploited vulnerabilities
- CVE-2021-44228 (vulnerability)
Reports & references
- i.blackhat.com — As 22 Li To Loot Or Not To Loot That Is Not A Question (report)
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- Microsoft — Guidance For Preventing Detecting And Hunting For Cve 2021 44228 Log4J 2 Exploitation (report)
- sentinelone.com — Lockbit Ransomware Side Loads Cobalt Strike Beacon With Legitimate Vmware Utility (report)
- twitter.com — 1480734487000453121 (report)
- blog.sygnia.co — Revealing Emperor Dragonfly A Chinese Ransomware Group (report)
- sentinelone.com — Chinese Entanglement Dll Hijacking In The Asian Gambling Sector (report)
- secureworks.com — Bronze Starlight Ransomware Operations Use Hui Loader (report)
- MITRE ATT&CK — G1021 (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)
- secureworks.com — Bronze Starlight (report)
- Trend Micro — New Linux Based Ransomware Cheerscrypt Targets Exsi Devices (report)
External references
- mitre-attack — G1021
- BRONZE STARLIGHT
- DEV-0401
- Emperor Dragonfly
- Sygnia Emperor Dragonfly October 2022
- SecureWorks BRONZE STARLIGHT Ransomware Operations June 2022
- Trend Micro Cheerscrypt May 2022
- Microsoft Threat Actor Naming July 2023
- Microsoft Ransomware as a Service
- Dell SecureWorks BRONZE STARLIGHT Profile
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy