SLOW#TEMPEST is a malware threat cluster tracked for campaigns targeting Chinese-speaking users. The group has been observed using DLL sideloading to execute malicious payloads through loader components designed to evade analysis and detection. Reported tradecraft includes Control Flow Graph obfuscation, dynamic function resolution, and other anti-analysis measures intended to conceal loader logic and hinder reverse engineering. Associated payloads have included Cobalt Strike and Mimikatz, indicating post-compromise capability for credential access and broader hands-on-keyboard intrusion activity. Based on the available high-confidence reporting, SLOW#TEMPEST is best characterized as an intrusion set distinguished by stealthy malware loading and defense-evasion techniques rather than a fully attributed nation-state or ransomware actor. No corroborated country-of-origin, industry specialization, or extortion activity is established from the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
22 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cluster referenced in context of using a Cobalt Strike loader and targeting Chinese-speaking users.
Malware campaign using advanced obfuscation and DLL-sideloading to evade detection and deliver payloads in memory.
Malware activity cluster using advanced obfuscation and commodity post-exploitation tooling, observed targeting Chinese-speaking users.
SLOW#TEMPEST is known for using advanced malware techniques, including DLL sideloading and anti-analysis measures, to evade detection and maintain persistence.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.