# Mustard Tempest

> As of 2026-06-24, Mustard Tempest is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning malware. Also known as DEV-0206, GOLD PRELUDE, Purple Vallhund, TA569. ATT&CK coverage spans 60 techniques across 14 tactics in 3 of 3 tracked threats. Most-observed techniques: T1082 (System Information Discovery), T1105 (Ingress Tool Transfer), T1189 (Drive-by Compromise).

- **Nation:** Russia
- **Tracked threats:** 3
- **Categories:** MALWARE
- **Also known as:** DEV-0206, GOLD PRELUDE, Purple Vallhund, TA569, UNC1543, SocGholish, FakeUpdates, Evil Corp, DEV-0243, UNC2165, Manatee Tempest, TA2726
- **As of:** 2026-06-24

## ATT&CK techniques observed

60 techniques observed across 3 of 3 tracked threats. Tactics: Stealth (formerly Defense Evasion) (10), Execution (9), Command and Control (7), Discovery (7), Collection (5), Credential Access (4).

- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 3 of 3 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 3 of 3 tracked threats
- [T1189](https://intel.threadlinqs.com/technique/T1189) Drive-by Compromise — Initial Access — observed in 3 of 3 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 2 of 3 tracked threats
- [T1016](https://intel.threadlinqs.com/technique/T1016) System Network Configuration Discovery — Discovery — observed in 2 of 3 tracked threats
- [T1033](https://intel.threadlinqs.com/technique/T1033) System Owner/User Discovery — Discovery — observed in 2 of 3 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1047](https://intel.threadlinqs.com/technique/T1047) Windows Management Instrumentation — Execution — observed in 2 of 3 tracked threats
- [T1055](https://intel.threadlinqs.com/technique/T1055) Process Injection — Privilege Escalation — observed in 2 of 3 tracked threats
- [T1057](https://intel.threadlinqs.com/technique/T1057) Process Discovery — Discovery — observed in 2 of 3 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 2 of 3 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 2 of 3 tracked threats
- [T1090](https://intel.threadlinqs.com/technique/T1090) Proxy — Command and Control — observed in 2 of 3 tracked threats
- [T1102](https://intel.threadlinqs.com/technique/T1102) Web Service — Command and Control — observed in 2 of 3 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats

## Tracked threats

- [Operation Endgame: Global Law Enforcement Takedown Disrupts SocGholish, Amadey, and StealC Malware-as-a-Service Networks](https://intel.threadlinqs.com/threat/TL-2026-0937) — HIGH
- [Operation Endgame Dismantles SocGholish (FakeUpdates) Initial-Access Malware Network — 106 Servers and 101 Domains Seized (TA569 / Evil Corp)](https://intel.threadlinqs.com/threat/TL-2026-0863) — HIGH
- [International Law Enforcement Disrupts SocGholish (js.fakeupdates) Access-Broker Infrastructure Linked to Evil Corp](https://intel.threadlinqs.com/threat/TL-2026-0852) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Mustard%20Tempest
