Cinnamon Tempest

APT / StateG1021 ↗
Origin🇨🇳 China
Techniques (MITRE ATT&CK)19
SourceMITRE ATT&CK
0
Also known as:BRONZE STARLIGHTDEV-0401Emperor DragonflySLIME34

About the group

Cinnamon Tempest is a China-based threat group that has been active since at least 2021 deploying multiple strains of ransomware based on the leaked Babuk source code. Cinnamon Tempest does not operate their ransomware on an affiliate model or purchase access but appears to act independently in all stages of the attack lifecycle. Based on victimology, the short lifespan of each ransomware variant, and use of malware attributed to government-sponsored threat groups, Cinnamon Tempest may be motivated by intellectual property theft or cyberespionage rather than financial gain.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity52
Impact: High
T1190T1047T1543.003T1021.002T1567.002ENTRYInitial accessExploitPublic-Facing App…EXECExecutionWindows ManagementInstrumentationPERSPersistenceWindows ServiceLATLateral movementSMB/Windows AdminSharesEXFILExfiltrationExfiltration toCloud StorageIMPACTImpactFinancial Theft

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Techniques (MITRE ATT&CK) 19

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Exploited vulnerabilities 2

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

Known infrastructure 3622

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

ip:port114.215.184.158:8000Cobalt Strikethreatfox
urlhttp://69.49.229.88:443/MQEwCobalt Strikethreatfox
ip:port154.12.17.20:8080Cobalt Strikethreatfox
ip:port154.12.17.20:22Cobalt Strikethreatfox
ip:port154.12.17.20:80Cobalt Strikethreatfox
ip:port154.12.17.20:443Cobalt Strikethreatfox
ip:port129.204.55.230:443Cobalt Strikethreatfox
ip:port47.94.56.71:8080Cobalt Strikethreatfox
ip:port47.94.56.71:80Cobalt Strikethreatfox
ip:port47.94.56.71:443Cobalt Strikethreatfox
md5_hashef5ebe165dc61a588e448f5a045f545dSliverthreatfox
sha1_hashfb7fc0a4b77adfe1388efd7d08e113ee6abc142eSliverthreatfox
sha256_hash01c6597a9d807338577300a4c861509021b161784c7997d70e4bd44d4da2c059Sliverthreatfox
ip:port45.227.253.132:8080Cobalt Strikethreatfox
ip:port45.227.253.132:443Cobalt Strikethreatfox
ip:port45.227.253.132:80Cobalt Strikethreatfox
ip:port45.227.253.132:32775Cobalt Strikethreatfox
ip:port117.158.148.164:65535Cobalt Strikethreatfox
ip:port38.76.190.209:8888Cobalt Strikethreatfox
ip:port188.227.14.105:8080Cobalt Strikethreatfox
ip:port186.241.115.168:12443Cobalt Strikethreatfox
ip:port109.206.247.245:10881Cobalt Strikethreatfox
ip:port43.134.112.45:7500Cobalt Strikethreatfox
ip:port43.134.112.45:80Cobalt Strikethreatfox
ip:port43.134.112.45:8080Cobalt Strikethreatfox
ip:port43.134.112.45:7000Cobalt Strikethreatfox
ip:port43.134.112.45:443Cobalt Strikethreatfox
ip:port43.134.112.45:22Cobalt Strikethreatfox
urlhttp://http:/f.pylrk.cc/HaKi2ufpiQ8AeVTZ/hostSliverthreatfox
md5_hashbe02c9890e938e672165c1c10bc99bb2Sliverthreatfox

+3622 indicators in total. See them all on the IOCs page.

Cinnamon Tempest uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →