The Fox Tempest Question
ID: e3890ed6-f98f-5f22-a7f2-0954bf55ebfe
STIX ID: report--e3890ed6-f98f-5f22-a7f2-0954bf55ebfe
Feed Name: Ransomware ISAC Blog
This report documents a sophisticated malware campaign in which a single build lineage was routed through two separate code-signing chains (a revoked Certum corporate shell cert for a loader and a Microsoft Trusted Signing individual cert for an info stealer), uses client-side FNV-1a fingerprinting at idantre.com and a Telegram-based remote shell for payload delivery and persistence, provides IOCs (file hashes, domain, signer identities, and an active Telegram bot token), and assesses medium confidence attribution to Dragon Breath/APT-Q-27 while highlighting sourcing via Fox Tempest MSaaS.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
