logo

The Fox Tempest Question

ID: e3890ed6-f98f-5f22-a7f2-0954bf55ebfe

STIX ID: report--e3890ed6-f98f-5f22-a7f2-0954bf55ebfe

Feed Name: Ransomware ISAC Blog

Threat Score
80/100

Date Published: 2026-07-20

Date Updated: 2026-09-11

Author: [email protected] (Alex Necula)

...
...

This report documents a sophisticated malware campaign in which a single build lineage was routed through two separate code-signing chains (a revoked Certum corporate shell cert for a loader and a Microsoft Trusted Signing individual cert for an info stealer), uses client-side FNV-1a fingerprinting at idantre.com and a Telegram-based remote shell for payload delivery and persistence, provides IOCs (file hashes, domain, signer identities, and an active Telegram bot token), and assesses medium confidence attribution to Dragon Breath/APT-Q-27 while highlighting sourcing via Fox Tempest MSaaS.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.