Threat actor · all actors
Mustard TempestG1020 unknown
aka Mustard Tempest, DEV-0206, TA569, GOLD PRELUDE, UNC1543, Purple Vallhund
Last updated: 2026-08-20
About this actor
[Mustard Tempest](https://attack.mitre.org/groups/G1020) is an initial access broker that has operated the [SocGholish](https://attack.mitre.org/software/S1124) distribution network since at least 2017. [Mustard Tempest](https://attack.mitre.org/groups/G1020) has partnered with [Indrik Spider](https://attack.mitre.org/groups/G0119) to provide access for the download of additional malware including LockBit, [WastedLocker](https://attack.mitre.org/software/S0612), and remote access tools.(Citation: Microsoft Ransomware as a Service)(Citation: Microsoft Threat Actor Naming July 2023)(Citation: Secureworks Gold Prelude Profile)(Citation: SocGholish-update)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Microsoftweather-system names
MandiantUNC uncategorised cluster
Secureworkscolour-metal names
ProofpointTA threat-actor id
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 18 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1036Masquerading ↗T1036.005Match Legitimate Resource Name or Location ↗T1082System Information Discovery ↗T1105Ingress Tool Transfer ↗T1189Drive-by Compromise ↗T1204User Execution ↗T1204.001Malicious Link ↗T1566Phishing ↗T1566.002Spearphishing Link ↗T1583Acquire Infrastructure ↗T1583.004Server ↗T1583.008Malvertising ↗T1584Compromise Infrastructure ↗T1584.001Domains ↗T1608Stage Capabilities ↗T1608.001Upload Malware ↗T1608.004Drive-by Target ↗T1608.006SEO Poisoning ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
CA-7 | 8 / 18 | 44% |
CM-2 | 8 / 18 | 44% |
CM-6 | 8 / 18 | 44% |
SI-3 | 8 / 18 | 44% |
SI-4 | 8 / 18 | 44% |
AC-4 | 6 / 18 | 33% |
SC-7 | 6 / 18 | 33% |
CM-7 | 5 / 18 | 28% |
IA-9 | 4 / 18 | 22% |
SC-44 | 4 / 18 | 22% |
SI-2 | 4 / 18 | 22% |
SI-7 | 4 / 18 | 22% |
SI-8 | 4 / 18 | 22% |
AC-6 | 3 / 18 | 17% |
SI-10 | 3 / 18 | 17% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- Transparent Tribe 0.41
- C0010 0.33
- SideCopy 0.30
- C0021 0.29
- C0011 0.28