APT / THREAT GROUP

Amethyst Rain

🇱🇧LB-attributed
3
aliases
Last seen:Jul 8, 2026

Intelligence Profile

Microsoft threat actor profile. Origin/Threat: Lebanon.

Intelligence Assessment

Amethyst Rain, also known as Volatile Cedar and VolcanicTimber, is a threat group originating from Lebanon.

Amethyst Rain's tradecraft includes techniques such as server software discovery (T1595.002), exploiting public-facing applications (T1190), ingress tool transfer (T1105), vulnerability scanning (T1595.003), and web shell (T1505.003).

Outlook

Amethyst Rain is currently active, with its last observed activity on 2026-07-08.

Generated by the CTIWATCH analysis pipeline from this actor's tracked data (victims, campaigns, TTPs, activity). Attribution and assessments may be incomplete — verify against primary reporting before acting.

Threat Analysis

Amethyst Rain is a known-sophistication threat actor attributed to LB, engaged in cyber operations with a primary motivation of unknown activity patterns.

TTPs — Tactics, Techniques & Procedures (5)

T1595.002T1190T1105T1595.003T1505.003

External References

Quick Facts

TypeAPT / Threat Group
Origin🇱🇧 LB
Aliases3
SourceMalpedia

Also Known As

Volatile CedarVolcanicTimberAmethyst Rain

Research Links

Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.