Velvet Tempest, formerly tracked as DEV-0504 and listed under the alias ALPHA SPIDER, is a financially motivated cybercriminal group conducting human-operated ransomware attacks as a ransomware-as-a-service affiliate. Active since at least 2020, it has repeatedly switched ransomware payloads rather than remaining tied to a single operation. Its deployments have included Ryuk, REvil, BlackMatter, Conti, BlackCat/ALPHV, and LockBit. LockBit 3.0 deployments have been observed since August 2023, and subsequent activity has included Termite ransomware. Confirmed targeting includes organizations in the energy sector. The group purchases compromised network access from initial-access brokers and also accesses systems using compromised credentials. It uses Cobalt Strike Beacons for post-exploitation, lateral movement, and payload staging, and relies heavily on PsExec for remote execution and ransomware distribution. Its intrusion activities include domain reconnaissance, credential theft using Mimikatz and Rubeus, and disabling antivirus products that lack tamper protection. ClickFix campaigns have also led to Termite ransomware attacks attributed to the group. Velvet Tempest is associated with the creation and use of Exmatter, a custom tool that automates collection and exfiltration of selected files before ransomware deployment. Observed Exmatter variants support network-share discovery, remote execution, and file-ownership changes when running with administrative privileges. The group has also used StealBit for data exfiltration. Its operations combine data theft and encryption to support double extortion. Its affiliate activity is distinct from the development and administration of the ransomware services whose payloads it deploys.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operator attributed with a ClickFix-driven intrusion culminating in hands-on-keyboard activity and deployment of Termite ransomware.
Operator attributed to a ClickFix-driven intrusion culminating in hands-on-keyboard activity and deployment of Termite ransomware.
Linked to a ClickFix-driven intrusion chain that culminates in hands-on-keyboard activity and deployment of Termite ransomware.
Financially motivated threat actor tracked by Microsoft under the Tempest family.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.