All threat actors

Cinnamon Tempest

Alert me

Cinnamon Tempest is a China-based threat group associated with the aliases DEV-0401, Emperor Dragonfly, and BRONZE STARLIGHT. Active since at least 2021, it has deployed multiple ransomware strains based on the leaked Babuk source code. Unlike typical ransomware operations, Cinnamon Tempest does not use an affiliate model or purchase access, instead acting independently throughout the attack lifecycle. The group's activities suggest a focus on intellectual property theft or cyberespionage rather than financial gain.

Also known as

BRONZE STARLIGHT
DEV-0401
Emperor Dragonfly

Create a free account to see the reports

Sign in or create a free account to see every report that names Cinnamon Tempest.

Create free account