19
Techniques
8
Toolsets
2
CVEs Referenced
1
KEV Entries
CISA Known Exploited
About Cinnamon Tempest

Cinnamon Tempest is a China-based threat group that has been active since at least 2021 deploying multiple strains of ransomware based on the leaked Babuk source code. Cinnamon Tempest does not operate their ransomware on an affiliate model or purchase access but appears to act independently in all stages of the attack lifecycle. Based on victimology, the short lifespan of each ransomware variant, and use of malware attributed to government-sponsored threat groups, Cinnamon Tempest may be motivated by intellectual property theft or cyberespionage rather than financial gain.

View MITRE record ↗

Toolsets (8)
🐛
Malware · Windows, ESXi
🐛
Malware · Linux, macOS, Windows
🐛
Malware · Windows
🐛
Pandora S0664
Malware · Windows
🐛
PlugX S0013
Malware · Windows
🔧
Impacket S0357
Tool · Linux, macOS, Windows
🔧
Rclone S1040
Tool · Linux, Windows, macOS
🔧
Sliver S0633
Tool · Windows, Linux, macOS
CVEs Referenced (2 · 1 CISA KEV)
CVE-2014-7169View full details on NVDKEV
CVE-2016-6662View full details on NVD
↑