Threadlinqs IntelligenceStart free

Threat actorRussiaTracked since 2026-06

Mustard Tempest

Also known as:DEV-0206GOLD PRELUDEPurple VallhundTA569UNC1543SocGholishFakeUpdatesEvil CorpDEV-0243UNC2165Manatee TempestTA2726

As of 2026-06-24, Mustard Tempest is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning malware. Also known as DEV-0206, GOLD PRELUDE, Purple Vallhund, TA569. ATT&CK coverage spans 60 techniques across 14 tactics in 3 of 3 tracked threats. Most-observed techniques: T1082 (System Information Discovery), T1105 (Ingress Tool Transfer), T1189 (Drive-by Compromise).

Tracked threats
33 high
First seen
2026-06-18
Last seen
2026-06-24
ATT&CK techniques
60across 3 of 3 threats
Related CVEs
0None referenced
Attribution
RussiaNation or origin
Nation: Russia · 3 tracked threat(s) · Categories: MALWARE

Activity timeline

Mustard Tempest appears in 3 tracked threats between and .

ATT&CK techniques observed

60 techniques observed across 3 of 3 tracked threats · Stealth (formerly Defense Evasion) (10), Execution (9), Command and Control (7), Discovery (7), Collection (5), Credential Access (4)
  • T1082 System Information Discovery — Discoveryobserved in 3 of 3 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 3 of 3 tracked threats
  • T1189 Drive-by Compromise — Initial Accessobserved in 3 of 3 tracked threats
  • T1005 Data from Local System — Collectionobserved in 2 of 3 tracked threats
  • T1016 System Network Configuration Discovery — Discoveryobserved in 2 of 3 tracked threats
  • T1033 System Owner/User Discovery — Discoveryobserved in 2 of 3 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
  • T1047 Windows Management Instrumentation — Executionobserved in 2 of 3 tracked threats
  • T1055 Process Injection — Privilege Escalationobserved in 2 of 3 tracked threats
  • T1057 Process Discovery — Discoveryobserved in 2 of 3 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 2 of 3 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 2 of 3 tracked threats
  • T1090 Proxy — Command and Controlobserved in 2 of 3 tracked threats
  • T1102 Web Service — Command and Controlobserved in 2 of 3 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats

Tracked threats