Velvet Tempest, also tracked as DEV-0504 and associated in some reporting with alpha_spider, is a financially motivated cybercriminal intrusion cluster operating as a prolific ransomware affiliate. The actor is known for deploying multiple ransomware-as-a-service payloads since 2020, including BlackCat/ALPHV and later Termite, illustrating a payload-agnostic, hands-on-keyboard operating model rather than loyalty to a single ransomware brand. Velvet Tempest has been identified as an affiliate of the ALPHV/BlackCat ecosystem and has also been linked to campaigns that transitioned from social-engineering-driven initial access into interactive ransomware deployment. The group commonly relies on compromised credentials and access brokers for initial access, including remote sign-in to exposed systems. It has also been associated with ClickFix-style lures in campaigns that culminated in ransomware deployment. Post-compromise activity includes domain and environment discovery, credential theft using tools such as Mimikatz and Rubeus, extensive use of Cobalt Strike for command and control and post-exploitation, and lateral movement with PsExec. The actor has been observed disabling inadequately protected antivirus products, using legitimate administrative mechanisms to expand access, and exfiltrating victim data prior to ransomware execution, including use of tooling associated with ALPHV data theft operations. Velvet Tempest has targeted organizations in the energy sector and other enterprise environments. Its tradecraft is consistent with modern double-extortion ransomware intrusions in which data theft and operational disruption are combined to pressure victims into payment. The actor is best understood as a financially motivated affiliate cluster within the broader ransomware ecosystem rather than as a nation-state operator.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operator attributed with a ClickFix-driven intrusion culminating in hands-on-keyboard activity and deployment of Termite ransomware.
Operator attributed to a ClickFix-driven intrusion culminating in hands-on-keyboard activity and deployment of Termite ransomware.
Linked to a ClickFix-driven intrusion chain that culminates in hands-on-keyboard activity and deployment of Termite ransomware.
Financially motivated threat actor tracked by Microsoft under the Tempest family.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.