FlagThis
← Threat Actors
/
Global
/
Vanilla Tempest
DOSSIER // VANILLA-TEMPEST
Vanilla Tempest
ACTIVE CAMPAIGN TRACKED
▲ High Threat
Primary Aliases:
DEV-0832
VICE SPIDER
Vice Society
📋 Copy All
Primary Motivation
Financial gain via data extortion
Confidence Rating
85% (Grounded)
APAC Regional Extortion Campaign
📥 Export ATT&CK Layer (.json)
🔔 RSS Feed
🏛️ CISA Advisories ↗
📋 Copy Dossier Briefing
🎯 Target Sectors & Focus
Healthcare
Government
Critical Infrastructure
Manufacturing
Financial Services
🛡️ MITRE ATT&CK® Attack Lifecycle
(7 TTPs)
📥 Download Navigator JSON
All Stages
7
Initial Access
1
Execution
1
Credential Access & Discovery
1
Lateral Movement & Collection
1
Command & Control
1
Operational Techniques
2
Initial Access
1
T1566
Exploitation of Public-Facing Applications
↗
Execution
1
T1059
Living-off-the-Land (LotL)
↗
Credential Access & Discovery
1
T1003
Credential Access
↗
Lateral Movement & Collection
1
T1021
Remote Desktop Protocol (RDP) Exploitation
↗
Command & Control
1
T1071
Data Exfiltration
↗
Operational Techniques
2
T1000
Cobalt Strike Deployment
↗
T1000
Vulnerability Exploitation (Edge Devices)
↗
Adversary Rosetta Stone // Vanilla Tempest
×
🪟 Microsoft Threat Actor Naming
DEV-0832
📋
🦅 CrowdStrike Monikers
VICE SPIDER
📋
🛡️ Other Industry Tracking Codes
Vice Society
📋
Copied to clipboard
SHARE INTELLIGENCE WIRE
×
Story Title
X / Twitter
Bluesky
LinkedIn
Copy Link
LINK COPIED TO CLIPBOARD