Threadlinqs IntelligenceStart free

Threat actorRussiaTracked since 2026-07

Periwinkle Tempest

Also known as:Wizard Spider

As of 2026-08-24, Periwinkle Tempest is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 5 threats spanning malware, ransomware. Also known as Wizard Spider. ATT&CK coverage spans 77 techniques across 14 tactics in 5 of 5 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1036 (Masquerading), T1082 (System Information Discovery).

Tracked threats
55 high
First seen
2026-07-10
Last seen
2026-08-24
ATT&CK techniques
77across 5 of 5 threats
Related CVEs
0None referenced
Attribution
RussiaNation or origin
Nation: Russia · 5 tracked threat(s) · Categories: MALWARE, RANSOMWARE

Activity timeline

Periwinkle Tempest appears in 5 tracked threats between and ; the busiest month was 2026-07 with 4 reports.

ATT&CK techniques observed

77 techniques observed across 5 of 5 tracked threats · Stealth (formerly Defense Evasion) (18), Command and Control (15), Discovery (10), Execution (9), Initial Access (5), Defense Impairment (4)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 5 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 4 of 5 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 4 of 5 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 5 tracked threats
  • T1016 System Network Configuration Discovery — Discoveryobserved in 3 of 5 tracked threats
  • T1021 Remote Services — Lateral Movementobserved in 3 of 5 tracked threats
  • T1053 Scheduled Task/Job — Persistenceobserved in 3 of 5 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 3 of 5 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 3 of 5 tracked threats
  • T1106 Native API — Executionobserved in 3 of 5 tracked threats
  • T1572 Protocol Tunneling — Command and Controlobserved in 3 of 5 tracked threats
  • T1003 OS Credential Dumping — Credential Accessobserved in 2 of 5 tracked threats
  • T1008 Fallback Channels — Command and Controlobserved in 2 of 5 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 2 of 5 tracked threats
  • T1053.005 Scheduled Task — Persistenceobserved in 2 of 5 tracked threats

Tracked threats