Threat Actor Characterization
Cinnamon Tempest
ID: ca33e5d87571c50773a94c774823a34264554| BRONZE STARLIGHT | DEV-0401 | Em*************** | — |
Actor Network Graph
Open Network GraphMITRE ATT&CK®
Cinnamon Tempest — China-nexus cluster using short-lived ransomware brands (LockFile/Rook/Night Sky/Pandora) with HUI Loader + Cobalt Strike; likely blends financial pressure with broader objectives.
| Technique | Technique name | Tactics | Evidence |
|---|---|---|---|
| T1190 | Exploit Public-Facing Application | TA0001 |
|
| T1105 | Ingress Tool Transfer | TA0011 |
|
| T1486 | Data Encrypted for Impact | TA0040 |
|
| T1078 | Valid Accounts | TA0001 TA0003 TA0004 TA0005 |
|
| T1041 | Exfiltration Over C2 Channel | TA0010 |
|
CLASSIFICATION: Unclassified / Open Source
Executive Summary
Cinnamon Tempest (a.k.a. DEV-0401, BRONZE STARLIGHT, Emperor Dragonfly) is a China-nexus cluster associated with a carousel of short-lived ransomware brands (e.g., LockFile, Rook, Night Sky, Pandora) likely used as operational cover for broader objectives. Reporting highlights HUI Loader + Cobalt Strike tradecraft, rapid edge exploitation, and opportunistic intrusions that may blend financial leverage with intelligence priorities. Confidence: high
Contractor-linked characteristics; overlaps in tooling (HUI Loader/ShadowPad lineage) with other China-nexus clusters. Campaigns are bursty, with visible rebrands and limited persistence in some cases.