# Periwinkle Tempest

> As of 2026-08-24, Periwinkle Tempest is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 5 threats spanning malware, ransomware. Also known as Wizard Spider. ATT&CK coverage spans 77 techniques across 14 tactics in 5 of 5 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1036 (Masquerading), T1082 (System Information Discovery).

- **Nation:** Russia
- **Tracked threats:** 5
- **Categories:** MALWARE, RANSOMWARE
- **Also known as:** Wizard Spider
- **As of:** 2026-08-24

## ATT&CK techniques observed

77 techniques observed across 5 of 5 tracked threats. Tactics: Stealth (formerly Defense Evasion) (18), Command and Control (15), Discovery (10), Execution (9), Initial Access (5), Defense Impairment (4).

- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 4 of 5 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 4 of 5 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 4 of 5 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 4 of 5 tracked threats
- [T1016](https://intel.threadlinqs.com/technique/T1016) System Network Configuration Discovery — Discovery — observed in 3 of 5 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 3 of 5 tracked threats
- [T1053](https://intel.threadlinqs.com/technique/T1053) Scheduled Task/Job — Persistence — observed in 3 of 5 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 3 of 5 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 3 of 5 tracked threats
- [T1106](https://intel.threadlinqs.com/technique/T1106) Native API — Execution — observed in 3 of 5 tracked threats
- [T1572](https://intel.threadlinqs.com/technique/T1572) Protocol Tunneling — Command and Control — observed in 3 of 5 tracked threats
- [T1003](https://intel.threadlinqs.com/technique/T1003) OS Credential Dumping — Credential Access — observed in 2 of 5 tracked threats
- [T1008](https://intel.threadlinqs.com/technique/T1008) Fallback Channels — Command and Control — observed in 2 of 5 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 2 of 5 tracked threats
- [T1053.005](https://intel.threadlinqs.com/technique/T1053.005) Scheduled Task — Persistence — observed in 2 of 5 tracked threats

## Tracked threats

- [TrickBot injectDLL Module: Man-in-the-Browser Web Injection Against Certificate Transparency](https://intel.threadlinqs.com/threat/TL-2026-2133) — HIGH
- [TrickBot Banking Trojan (Anchor_DNS) Uses DNS Tunneling Over westurn.in for Covert C2](https://intel.threadlinqs.com/threat/TL-2026-1684) — HIGH
- [TrickBot Malware Variant Adopts DNS Tunneling for C2 Communications (westurn.in)](https://intel.threadlinqs.com/threat/TL-2026-1651) — HIGH
- [SystemBC (Coroxy / DroxiDat) Malware: Multi-Purpose SOCKS5/Tor Proxy Backdoor Enabling Ransomware Operations](https://intel.threadlinqs.com/threat/TL-2026-1227) — HIGH
- [Armenian National Karen Vardanyan Pleads Guilty to Ryuk Ransomware Conspiracy (District of Oregon)](https://intel.threadlinqs.com/threat/TL-2026-1192) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Periwinkle%20Tempest
