SLOW#TEMPEST is a malware campaign/toolset publicly described by Unit 42 in July 2025. The reported malware uses DLL sideloading to launch a malicious DLL and employs anti-analysis and evasion techniques including Control Flow Graph (CFG) obfuscation, dynamic jumps, and obfuscated or dynamic function calls to conceal loader code and avoid detection. Reporting states the operators behind SLOW#TEMPEST were first observed targeting Chinese-speaking users and using payloads including Cobalt Strike and Mimikatz. High-confidence behaviors directly mentioned in the source content are DLL sideloading, advanced obfuscation in the loader DLL, and anti-analysis measures. The content does not provide specific industries, operating system details, or concrete indicators of compromise beyond these behavioral characteristics.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
SLOW#TEMPEST is a malware campaign using advanced obfuscation and DLL-sideloading to load malicious payloads in memory, evading detection and making mitigation challenging.
SLOW#TEMPEST is a malware family used by the SLOW#TEMPEST group, employing advanced obfuscation techniques to evade detection. It is used to deliver payloads such as Cobalt Strike and Mimikatz, primarily targeting Chinese-speaking users.
SLOW#TEMPEST is an advanced malware family employing techniques such as DLL sideloading and anti-analysis to evade detection and analysis. It is used in sophisticated attacks and is notable for its evolving tactics.
SLOW#TEMPEST is an advanced malware family employing techniques such as DLL sideloading and anti-analysis to evade detection and analysis. It is used in sophisticated attacks and is notable for its evolving tactics.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.