Evolving Tactics of SLOW#TEMPEST: A Deep Dive Into Advanced Malware Techniques
ID: 2806e459-48da-5d2e-807a-5aa39b0e201d
STIX ID: report--2806e459-48da-5d2e-807a-5aa39b0e201d
Feed Name: Palo Alto Networks Unit 42
Threat Score
This report analyzes a SLOW#TEMPEST malware variant: a loader DLL distributed inside an ISO and executed via DLL side-loading. It documents sophisticated obfuscation (dynamic jumps and indirect function calls), the use of emulation and IDAPython to de-obfuscate control flow and API resolution, provides SHA256 indicators and file details, and includes mitigation and detection guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
