Microsoft stated that Manatee Tempest was seen deploying RansomHub in post-compromise activity after Mustard Tempest gained access via FakeUpdates/Socgholish infections
According to Microsoft, the problem started on Thursday at 7 pm GMT and affected customers of the Azure cloud platform who were using CrowdStrike Falcon,