Cinnamon Tempest

MITRE ATT&CK: G1021 View on attack.mitre.org

Aliases: DEV-0401, Emperor Dragonfly, BRONZE STARLIGHT, SLIME34, Cinnamon Tempest, Bronze Starlight, HighGround

First seen
2021-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Related IoCs
3 (3 malicious)
Last IoC activity
2026-09-01 20:32:53
Profile updated
2026-07-07 12:32:42

Targeted industries: government-and-public-sector technology-and-telecommunications healthcare-and-pharmaceutical financial-services

Targeted regions: country_code:us country_code:cn country_code:gb country_code:fr

Context

Cinnamon Tempest is a China-based threat group that has been active since at least 2021 deploying multiple strains of ransomware based on the leaked Babuk source code. Cinnamon Tempest does not operate their ransomware on an affiliate model or purchase access but appears to act independently in all stages of the attack lifecycle. Based on victimology, the short lifespan of each ransomware variant, and use of malware attributed to government-sponsored threat groups, Cinnamon Tempest may be motivated by intellectual property theft or cyberespionage rather than financial gain.

Recent IoC activity

3 malicious indicators in Maltiverse are attributed to Cinnamon Tempest (G1021). The 3 most recently updated:

TypeIndicatorUpdatedSources
hostname microsofts.com 2026-09-03 1
hostname microupdate.xyz 2026-07-28 2
hostname duckducklive.top 2026-07-22 3

Detection coverage

  • 165 YARA rules
  • 673 Sigma rules

Malware & tools used

  • DLL (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Group Policy Modification (attack-pattern)
  • Exfiltration to Cloud Storage (attack-pattern)
  • Tool (attack-pattern)
  • Valid Accounts (attack-pattern)
  • Financial Theft (attack-pattern)
  • Proxy (attack-pattern)
  • Domain Accounts (attack-pattern)
  • Exploit Public-Facing Application (attack-pattern)
  • Python (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • SMB/Windows Admin Shares (attack-pattern)
  • Protocol Tunneling (attack-pattern)
  • Taint Shared Content (attack-pattern)
  • Windows Service (attack-pattern)
  • PowerShell (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Sliver (malware)
  • Impacket (malware)
  • HUI Loader (malware)
  • Rclone (malware)
  • Cheerscrypt (malware)
  • PlugX (malware)

Exploited vulnerabilities

  • CVE-2021-44228 (vulnerability)

Reports & references

  • i.blackhat.com — As 22 Li To Loot Or Not To Loot That Is Not A Question (report)
  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • Microsoft — Guidance For Preventing Detecting And Hunting For Cve 2021 44228 Log4J 2 Exploitation (report)
  • sentinelone.com — Lockbit Ransomware Side Loads Cobalt Strike Beacon With Legitimate Vmware Utility (report)
  • twitter.com — 1480734487000453121 (report)
  • blog.sygnia.co — Revealing Emperor Dragonfly A Chinese Ransomware Group (report)
  • sentinelone.com — Chinese Entanglement Dll Hijacking In The Asian Gambling Sector (report)
  • secureworks.com — Bronze Starlight Ransomware Operations Use Hui Loader (report)
  • MITRE ATT&CK — G1021 (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)
  • secureworks.com — Bronze Starlight (report)
  • Trend Micro — New Linux Based Ransomware Cheerscrypt Targets Exsi Devices (report)

External references