# Vanilla Tempest

> As of 2026-09-06, Vanilla Tempest is a threat actor tracked by Threadlinqs Intelligence across 3 threats spanning ransomware, malware. Also known as Rapid Brigantine, Vice Society, DEV-0832, VICE SPIDER. ATT&CK coverage spans 65 techniques across 15 tactics in 3 of 3 tracked threats. Most-observed techniques: T1053.005 (Scheduled Task), T1059.001 (PowerShell), T1059.003 (Windows Command Shell).

- **Tracked threats:** 3
- **Categories:** RANSOMWARE, MALWARE
- **Also known as:** Rapid Brigantine, Vice Society, DEV-0832, VICE SPIDER
- **As of:** 2026-09-06

## ATT&CK techniques observed

65 techniques observed across 3 of 3 tracked threats. Tactics: Stealth (formerly Defense Evasion) (12), Resource Development (11), Command and Control (9), Execution (8), Discovery (7), Defense Impairment (3).

- [T1053.005](https://intel.threadlinqs.com/technique/T1053.005) Scheduled Task — Persistence — observed in 2 of 3 tracked threats
- [T1059.001](https://intel.threadlinqs.com/technique/T1059.001) PowerShell — Execution — observed in 2 of 3 tracked threats
- [T1059.003](https://intel.threadlinqs.com/technique/T1059.003) Windows Command Shell — Execution — observed in 2 of 3 tracked threats
- [T1069.002](https://intel.threadlinqs.com/technique/T1069.002) Domain Groups — Discovery — observed in 2 of 3 tracked threats
- [T1087.002](https://intel.threadlinqs.com/technique/T1087.002) Account Discovery: Domain Account — Discovery — observed in 2 of 3 tracked threats
- [T1102.001](https://intel.threadlinqs.com/technique/T1102.001) Dead Drop Resolver — Command and Control — observed in 2 of 3 tracked threats
- [T1218.007](https://intel.threadlinqs.com/technique/T1218.007) Msiexec — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1482](https://intel.threadlinqs.com/technique/T1482) Domain Trust Discovery — Discovery — observed in 2 of 3 tracked threats
- [T1547.001](https://intel.threadlinqs.com/technique/T1547.001) Registry Run Keys / Startup Folder — Persistence — observed in 2 of 3 tracked threats
- [T1553.002](https://intel.threadlinqs.com/technique/T1553.002) Code Signing — Defense Impairment — observed in 2 of 3 tracked threats
- [T1574.001](https://intel.threadlinqs.com/technique/T1574.001) DLL — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1583.006](https://intel.threadlinqs.com/technique/T1583.006) Acquire Infrastructure: Web Services — Resource Development — observed in 2 of 3 tracked threats
- [T1588.002](https://intel.threadlinqs.com/technique/T1588.002) Tool — Resource Development — observed in 2 of 3 tracked threats
- [T1001.002](https://attack.mitre.org/techniques/T1001/002/) Steganography — Command and Control — observed in 1 of 3 tracked threats
- [T1003.003](https://intel.threadlinqs.com/technique/T1003.003) NTDS — Credential Access — observed in 1 of 3 tracked threats

## Tracked threats

- [Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)](https://intel.threadlinqs.com/threat/TL-2026-2357) — CRITICAL
- [ClickFix Cluster Uses DLL Sideloading and Compromised WordPress Sites to Deliver Lorem Ipsum Loader, Linked to Vanilla Tempest](https://intel.threadlinqs.com/threat/TL-2026-2199) — HIGH
- [Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via SEO-Poisoned Trojanized Microsoft Teams Installers](https://intel.threadlinqs.com/threat/TL-2026-0822) — HIGH

## Related CVEs

1 CVE referenced by tracked Vanilla Tempest activity.

- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Vanilla%20Tempest
