Velvet Tempest

Aliases: DEV-0504, ALPHA SPIDER

Primary motivation
financial-gain
Sophistication
advanced
Resource level
team
Actor type
criminal
Profile updated
2026-07-07 12:34:36

Targeted industries: energy-and-utilities manufacturing technology-and-telecommunications retail-and-hospitality

Context

Velvet Tempest is a threat actor associated with the BlackCat ransomware group. They have been observed deploying multiple ransomware payloads, including BlackCat, and have targeted various industries such as energy, fashion, tobacco, IT, and manufacturing. Velvet Tempest relies on access brokers to gain network access and utilizes tools like Cobalt Strike Beacons and PsExec for lateral movement and payload staging. They exfiltrate stolen data using a tool called StealBit and frequently disable unprotected antivirus products.

Related threat objects

Reports & references

  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • Microsoft — The Many Lives Of Blackcat Ransomware (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)

External references