CyberSecurityBoardThreat Intel · CVEs · Products
Attack Groups

Mustard Tempest

March 25, 2024

[Mustard Tempest](https://attack.mitre.org/groups/G1020) is an initial access broker that has operated the [SocGholish](https://attack.mitre.org/software/S1124) distribution network since at least 2017. [Mustard Tempest](https://attack.mitre.org/groups/G1020) has partnered with [Indrik Spider](https://attack.mitre.org/groups/G0119) to provide access for the download of additional malware including LockBit, [WastedLocker](https://attack.mitre.org/software/S0612), and remote access tools.(Citation: Microsoft Ransomware as a Service)(Citation: Microsoft Threat Actor Naming July 2023)(Citation: Secureworks Gold Prelude Profile)(Citation: SocGholish-update)

Aliases: Mustard Tempest, DEV-0206, TA569, GOLD PRELUDE, UNC1543

MITRE ATT&CK ID: G1020

View on MITRE ATT&CK