logo

Evolving Tactics of SLOW#TEMPEST: A Deep Dive Into Advanced Malware Techniques

ID: 2806e459-48da-5d2e-807a-5aa39b0e201d

STIX ID: report--2806e459-48da-5d2e-807a-5aa39b0e201d

Feed Name: Palo Alto Networks Unit 42

Threat Score
70/100

Date Published: 2025-07-11

Date Updated: 2026-04-28

Author: Mark Lim

...
...

This report analyzes a SLOW#TEMPEST malware variant: a loader DLL distributed inside an ISO and executed via DLL side-loading. It documents sophisticated obfuscation (dynamic jumps and indirect function calls), the use of emulation and IDAPython to de-obfuscate control flow and API resolution, provides SHA256 indicators and file details, and includes mitigation and detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.