Velvet Tempest, previously tracked by Microsoft as DEV-0504 and also associated in reporting with Alpha Spider, is a financially motivated ransomware affiliate cluster operating in the ransomware-as-a-service ecosystem. The cluster is notable for repeatedly switching between ransomware payloads rather than being tied to a single family, and has been linked over time to Ryuk, REvil, LockBit, BlackMatter, Conti, BlackCat/ALPHV, and later Termite activity. It has also been identified as an affiliate of the ALPHV/BlackCat operation. The actor’s tradecraft is characteristic of hands-on-keyboard enterprise ransomware intrusions. Reported initial access methods include use of compromised credentials, remote sign-in to exposed systems, and access obtained through brokers or malware ecosystems. Velvet Tempest has been associated with use of IcedID as an access-enabling malware source and with Cobalt Strike for post-compromise operations. After gaining access, the actor conducts internal discovery, steals credentials with tools such as Mimikatz and Rubeus, escalates privileges, and moves laterally using administrative mechanisms including PsExec and remote execution over network shares or Group Policy. A defining feature of Velvet Tempest activity is pre-encryption data theft. Microsoft attributed the creation and use of the ExMatter exfiltration tool to this actor. ExMatter has been used to automate collection of targeted enterprise data, enumerate accessible storage including mapped network resources, remotely execute across systems, and exfiltrate large volumes of files prior to ransomware deployment. This supports double-extortion operations in which stolen data is used to pressure victims in addition to encryption. Velvet Tempest has also been observed disabling or tampering with insufficiently protected security tooling, relying on legitimate administration utilities for stealth and scale, and deploying ransomware broadly across victim environments once privileged access is obtained. Reported campaigns include intrusions affecting the energy sector and later activity involving deployment of the Termite ransomware following ClickFix-style social engineering. Overall, Velvet Tempest is best understood as a prolific, adaptable ransomware affiliate cluster whose core capability lies in intrusion operations, credential abuse, lateral movement, data exfiltration, and flexible use of multiple extortion payloads.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operator attributed with a ClickFix-driven intrusion culminating in hands-on-keyboard activity and deployment of Termite ransomware.
Operator attributed to a ClickFix-driven intrusion culminating in hands-on-keyboard activity and deployment of Termite ransomware.
Linked to a ClickFix-driven intrusion chain that culminates in hands-on-keyboard activity and deployment of Termite ransomware.
Financially motivated threat actor tracked by Microsoft under the Tempest family.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.