Activity timeline
Mustard Tempest appears in 3 tracked threats between and .
ATT&CK techniques observed
- T1082 System Information Discovery — Discoveryobserved in 3 of 3 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 3 of 3 tracked threats
- T1189 Drive-by Compromise — Initial Accessobserved in 3 of 3 tracked threats
- T1005 Data from Local System — Collectionobserved in 2 of 3 tracked threats
- T1016 System Network Configuration Discovery — Discoveryobserved in 2 of 3 tracked threats
- T1033 System Owner/User Discovery — Discoveryobserved in 2 of 3 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
- T1047 Windows Management Instrumentation — Executionobserved in 2 of 3 tracked threats
- T1055 Process Injection — Privilege Escalationobserved in 2 of 3 tracked threats
- T1057 Process Discovery — Discoveryobserved in 2 of 3 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 2 of 3 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 2 of 3 tracked threats
- T1090 Proxy — Command and Controlobserved in 2 of 3 tracked threats
- T1102 Web Service — Command and Controlobserved in 2 of 3 tracked threats
- T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
Tracked threats
- Operation Endgame: Global Law Enforcement Takedown Disrupts SocGholish, Amadey, and StealC Malware-as-a-Service NetworksHIGH
- Operation Endgame Dismantles SocGholish (FakeUpdates) Initial-Access Malware Network — 106 Servers and 101 Domains Seized (TA569 / Evil Corp)HIGH
- International Law Enforcement Disrupts SocGholish (js.fakeupdates) Access-Broker Infrastructure Linked to Evil CorpHIGH