BRONZE STARLIGHTBRONZE STARLIGHT

Also known as: BRONZE STARLIGHT · SLIME34 · DEV-0401 · Cinnamon Tempest · Emperor Dragonfly

Known aliases
5

Profile

BRONZE STARLIGHT has been active since mid 2021 and targets organizations globally across a range of industry verticals. The group leverages HUI Loader to load Cobalt Strike and PlugX payloads for command and control. CTU researchers have observed BRONZE STARLIGHT deploying ransomware to compromised networks as part of name-and-shame ransomware schemes, and posted victim names to leak sites. CTU researchers assess with moderate confidence that BRONZE STARLIGHT is located in China based on observed tradecraft, including the use of HUI Loader and PlugX which are associated with China-based threat group activity. It is plausible that BRONZE STARLIGHT deploys ransomware as a smokescreen rather than for financial gain, with the underlying motivation of stealing intellectual property theft or conducting espionage.

Aliases· 5

BRONZE STARLIGHTSLIME34DEV-0401Cinnamon TempestEmperor Dragonfly

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
BRONZE VAPOR
Actor
BRONZE HIGHLAND
Actor
BRONZE EDGEWOOD
Actor
BRONZE SPRING
Actor
BRONZE SPIRAL
Actor
Volt Typhoon
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.