G1021: Cinnamon Tempest
Cinnamon Tempest is a China-based threat group that has been active since at least 2021 deploying multiple strains of ransomware based on the leaked Babuk source code. Cinnamon Tempest does not operate their ransomware on an affiliate model or purchase access but appears to act independently in all stages of the attack lifecycle. Based on victimology, the short lifespan of each ransomware variant, and use of malware attributed to government-sponsored threat groups, Cinnamon Tempest may be motivated by intellectual property theft or cyberespionage rather than financial gain.[1][2][3][4]
Security context for executives and security teams
G1021: Cinnamon Tempest describes [Cinnamon Tempest](https://attack.mitre.org/groups/G1021) is a China-based threat group that has been active since at least 2021 deploying multiple strains of ransomware based on the leaked [Babuk](https://attack.mitre.org/software/S0638) source code. [Cinnamon Tempest](https://attack.mitre.org/groups/G1021) does not operate their ransomware on an affiliate model or purchase access but appears to act independently in all stages of the attack lifecycle. Based on victimology, the short lifespan of each ransomware var...
Executive priority
G1021: Cinnamon Tempest is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate G1021: Cinnamon Tempest by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
Detection direction
- Validate whether G1021: Cinnamon Tempest appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Cinnamon Tempest
Cinnamon Tempest is a China-based threat group that has been active since at least 2021 deploying multiple strains of ransomware based on the leaked Babuk source code. Cinnamon Tempest does not operate their ransomware on an affiliate model or purchase access but appears to act independently in all stages of the attack lifecycle. Based on victimology, the short lifespan of each ransomware variant, and use of malware attributed to government-sponsored threat groups, Cinnamon Tempest may be motivated by intellectual property theft or cyberespionage rather than financial gain.[1][2][3][4]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1047 | Windows Management Instrumentation | Cinnamon Tempest has used Impacket for lateral movement via WMI.[1][5] |
| Enterprise | T1574.001 | DLLSub-technique | Cinnamon Tempest has used search order hijacking to launch Cobalt Strike Beacons.[1][4] Cinnamon Tempest has also abused legitimate executables to side-load weaponized DLLs.[5] |
| Enterprise | T1105 | Ingress Tool Transfer | Cinnamon Tempest has downloaded files, including Cobalt Strike, to compromised hosts.[5] |
| Enterprise | T1484.001 | Group Policy ModificationSub-technique | Cinnamon Tempest has used Group Policy to deploy batch scripts for ransomware deployment.[1] |
| Enterprise | T1567.002 | Exfiltration to Cloud StorageSub-technique | Cinnamon Tempest has uploaded captured keystroke logs to the Alibaba Cloud Object Storage Service, Aliyun OSS.[5] |
| Enterprise | T1588.002 | ToolSub-technique | Cinnamon Tempest has used open-source tools including customized versions of the Iox proxy tool, NPS tunneling tool, Meterpreter, and a keylogger that uploads data to Alibaba cloud storage.[5][4] |
| Enterprise | T1078 | Valid Accounts | Cinnamon Tempest has used compromised user accounts to deploy payloads and create system services.[5] |
| Enterprise | T1657 | Financial Theft | Cinnamon Tempest has maintained leak sites for exfiltrated data in attempt to extort victims into paying a ransom.[1] |
| Enterprise | T1090 | Proxy | Cinnamon Tempest has used a customized version of the Iox port-forwarding and proxy tool.[5] |
| Enterprise | T1078.002 | Domain AccountsSub-technique | Cinnamon Tempest has obtained highly privileged credentials such as domain administrator in order to deploy malware.[1] |
| Enterprise | T1190 | Exploit Public-Facing Application | Cinnamon Tempest has exploited multiple unpatched vulnerabilities for initial access including vulnerabilities in Microsoft Exchange, Manage Engine AdSelfService Plus, Confluence, and Log4j.[1]CitationMicrosoft Log4j Vulnerability Exploitation December 2021[5][4] |
| Enterprise | T1059.006 | PythonSub-technique | Cinnamon Tempest has used a customized version of the Impacket wmiexec.py module to create renamed output files.[1] |
| Enterprise | T1140 | Deobfuscate/Decode Files or Information | Cinnamon Tempest has used weaponized DLLs to load and decrypt payloads.[5] |
| Enterprise | T1021.002 | SMB/Windows Admin SharesSub-technique | Cinnamon Tempest has used SMBexec for lateral movement.[5] |
| Enterprise | T1572 | Protocol Tunneling | Cinnamon Tempest has used the Iox and NPS proxy and tunneling tools in combination create multiple connections through a single tunnel.[5] |
| Enterprise | T1080 | Taint Shared Content | Cinnamon Tempest has deployed ransomware from a batch file in a network share.[1] |
| Enterprise | T1543.003 | Windows ServiceSub-technique | Cinnamon Tempest has created system services to establish persistence for deployed tooling.[5] |
| Enterprise | T1059.001 | PowerShellSub-technique | Cinnamon Tempest has used PowerShell to communicate with C2, download files, and execute reconnaissance commands.[5] |
| Enterprise | T1059.003 | Windows Command ShellSub-technique | Cinnamon Tempest has executed ransomware using batch scripts deployed via GPO.[1] |
Groups, software, and campaigns
S0633: Sliver
S0664: Pandora
Pandora is a multistage kernel rootkit with backdoor functionality that has been in use by Threat Group-3390 since at least 2020.[1]
S0013: PlugX
S1096: Cheerscrypt
Cheerscrypt is a ransomware that was developed by Cinnamon Tempest and has been used in attacks against ESXi and Windows environments since at least 2022. Cheerscrypt was derived from the leaked Babuk source code and has infrastructure overlaps with deployments of Night Sky ransomware, which was also derived from Babuk.[1][2]
S0357: Impacket
S0154: Cobalt Strike
Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.[1]
In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.[1]
S1097: HUI Loader
HUI Loader is a custom DLL loader that has been used since at least 2015 by China-based threat groups including Cinnamon Tempest and menuPass to deploy malware on compromised hosts. HUI Loader has been observed in campaigns loading SodaMaster, PlugX, Cobalt Strike, Komplex, and several strains of ransomware.[1]
S1040: Rclone
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 1.0 | Current bundle | 827f722ffb44… | ||
| 19.1 | 1.0 | Older bundle | c8ebd5578d48… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]Microsoft Ransomware as a Service
Microsoft. (2022, May 9). Ransomware as a service: Understanding the cybercrime gig economy and how to protect yourself. Retrieved March 10, 2023.
Open source URL - [2]Microsoft Threat Actor Naming July 2023
Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
Open source URL - [3]Trend Micro Cheerscrypt May 2022
Dela Cruz, A. et al. (2022, May 25). New Linux-Based Ransomware Cheerscrypt Targeting ESXi Devices Linked to Leaked Babuk Source Code. Retrieved December 19, 2023.
Open source URL - [4]SecureWorks BRONZE STARLIGHT Ransomware Operations June 2022
Counter Threat Unit Research Team . (2022, June 23). BRONZE STARLIGHT RANSOMWARE OPERATIONS USE HUI LOADER. Retrieved December 7, 2023.
Open source URL - [5]Sygnia Emperor Dragonfly October 2022
Biderman, O. et al. (2022, October 3). REVEALING EMPEROR DRAGONFLY: NIGHT SKY AND CHEERSCRYPT - A SINGLE RANSOMWARE GROUP. Retrieved December 6, 2023.
Open source URL - [6]Dell SecureWorks BRONZE STARLIGHT Profile
SecureWorks. (n.d.). BRONZE STARLIGHT. Retrieved December 6, 2023.
Open source URL - [7]BRONZE STARLIGHT
(Citation: Dell SecureWorks BRONZE STARLIGHT Profile)
- [8]DEV-0401
(Citation: Microsoft Threat Actor Naming July 2023)
- [9]Emperor Dragonfly
(Citation: Sygnia Emperor Dragonfly October 2022)
- [10]mitre-attackG1021Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
