logo

The Fox Tempest Question

ID: 0f956010-0bef-568f-bce2-229a323c7a8c

STIX ID: report--0f956010-0bef-568f-bce2-229a323c7a8c

Feed Name: Ransomware ISAC Blog

Threat Score
80/100

Date Published: 2026-07-20

Date Updated: 2026-07-29

Author: [email protected] (Alex Necula)

...
...

This report details a sophisticated malware-signing campaign that routes a matched build lineage through two separate code-signing trust chains—a Certum corporate shell certificate for a loader and a Microsoft Trusted Signing individual certificate for an information stealer—enabling a Telegram-based reverse shell, client-side device fingerprinting via idantre.com, aggressive persistence via a 1-minute scheduled task, and operational resilience through MSaaS-sourced certificates (Fox Tempest) potentially linked to Dragon Breath/APT-Q-27.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.