Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-06

Vanilla Tempest

Also known as:Rapid BrigantineVice SocietyDEV-0832VICE SPIDER

As of 2026-09-06, Vanilla Tempest is a threat actor tracked by Threadlinqs Intelligence across 3 threats spanning ransomware, malware. Also known as Rapid Brigantine, Vice Society, DEV-0832, VICE SPIDER. ATT&CK coverage spans 65 techniques across 15 tactics in 3 of 3 tracked threats. Most-observed techniques: T1053.005 (Scheduled Task), T1059.001 (PowerShell), T1059.003 (Windows Command Shell).

Tracked threats
31 critical · 2 high
First seen
2026-06-16
Last seen
2026-09-06
ATT&CK techniques
65across 3 of 3 threats
Related CVEs
1Referenced by its activity
3 tracked threat(s) · Categories: RANSOMWARE, MALWARE

Activity timeline

Vanilla Tempest appears in 3 tracked threats between and ; the busiest month was 2026-06 with 1 report.

ATT&CK techniques observed

65 techniques observed across 3 of 3 tracked threats · Stealth (formerly Defense Evasion) (12), Resource Development (11), Command and Control (9), Execution (8), Discovery (7), Defense Impairment (3)
  • T1053.005 Scheduled Task — Persistenceobserved in 2 of 3 tracked threats
  • T1059.001 PowerShell — Executionobserved in 2 of 3 tracked threats
  • T1059.003 Windows Command Shell — Executionobserved in 2 of 3 tracked threats
  • T1069.002 Domain Groups — Discoveryobserved in 2 of 3 tracked threats
  • T1087.002 Account Discovery: Domain Account — Discoveryobserved in 2 of 3 tracked threats
  • T1102.001 Dead Drop Resolver — Command and Controlobserved in 2 of 3 tracked threats
  • T1218.007 Msiexec — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
  • T1482 Domain Trust Discovery — Discoveryobserved in 2 of 3 tracked threats
  • T1547.001 Registry Run Keys / Startup Folder — Persistenceobserved in 2 of 3 tracked threats
  • T1553.002 Code Signing — Defense Impairmentobserved in 2 of 3 tracked threats
  • T1574.001 DLL — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
  • T1583.006 Acquire Infrastructure: Web Services — Resource Developmentobserved in 2 of 3 tracked threats
  • T1588.002 Tool — Resource Developmentobserved in 2 of 3 tracked threats
  • T1001.002 Steganography — Command and Controlobserved in 1 of 3 tracked threats
  • T1003.003 NTDS — Credential Accessobserved in 1 of 3 tracked threats

Tracked threats

Related CVEs

1 CVE referenced by tracked Vanilla Tempest activity