Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Attacks - SLOW#TEMPEST Campaign Targets Chinese Users with Advanced Tactics
Attacks Evasion Attacks Latest News Malware Network Security News & Analysis Security Social Engineering Threats and Vulnerabilities

SLOW#TEMPEST Campaign Targets Chinese Users with Advanced Tactics

ISB Staff ReporterBy ISB Staff ReporterSeptember 3, 2024Updated:November 8, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
SLOW#TEMPEST
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

A sophisticated cyber campaign, dubbed SLOW#TEMPEST, has been uncovered by the Securonix Threat Research team, targeting Chinese-speaking users. The attack, characterized by the deployment of Cobalt Strike payloads, managed to evade detection for over two weeks, demonstrating the malicious actors’ ability to establish persistence and move laterally within compromised systems.

SLOW#TEMPEST primarily targets victims in China, with evidence suggesting that the attack leverages phishing emails to deliver malicious ZIP files. The lure files and the command-and-control (C2) infrastructure are predominantly written in Chinese, reinforcing the likelihood that Chinese users are the primary targets.

The C2 infrastructure is hosted by Shenzhen Tencent Computer Systems Company Limited, another indication that the operation is focused on China.

How it Works

According to Securonix researchers Den Iuzvyk and Tim Peck, the attack begins with the distribution of ZIP files, some of which are password-protected – a technique previously used by Qakbot threat actors to bypass email-based antivirus software. Once the ZIP file is opened, users are presented with a shortcut (.lnk) file disguised as a .docx file, which, when executed, initiates the attack.

The malefactors employed DLL hijacking techniques to execute the Cobalt Strike implant, a well-known tool for covertly controlling infected systems. The implant was loaded via a renamed Microsoft executable, exploiting a DLL path traversal vulnerability—a method that enabled the attackers to maintain stealthy access to the system.

Post-Exploitation Activities

Once inside the target system, the bad actors set up staging directories and downloaded additional tools for reconnaissance and network scanning. These tools, including port scanners and credential dumpers, enabled the attackers to identify live hosts, open ports, and gather sensitive information.

They also established persistence through scheduled tasks and manipulated user accounts to maintain control over the compromised systems.

The gang then used Remote Desktop Protocol (RDP) to move laterally across the network, leveraging stolen credentials obtained through tools like Mimikatz. This allowed them to escalate privileges and compromise additional systems within the network.

The criminals’ use of BloodHound, a tool for Active Directory enumeration, further enabled them to map out the network and identify high-value targets.

Securonix recommendations

According to the researchers, the key indicators of compromise identified in this investigation serve as critical data points for security teams aiming to detect and respond to similar threats in their environments.

By understanding the methods and tools used by cyber criminals in this campaign, defenders can better prepare to protect their networks from these advanced persistent threats.

  • As this campaign likely originated from phishing emails, Securonix advises to refrain from downloading files or attachments from external sources, particularly if they were unsolicited. Be cautious with common file types such as zip, rar, iso, and pdf files. During this campaign, password-protected zip files were sometimes used.
  • Also, keep an eye on common malware staging directories, especially for script-related activity in world-writable directories. In this campaign, threat actors staged files in subdirectories within C:\ProgramData, C:\Windows\Temp, and the user’s %APPDATA% directory.
  • Throughout the various stages of the SLOW#TEMPEST campaign, bad actors used encrypted channels over multiple ports to avoid detection. Therefore, Securonix strongly recommends implementing robust endpoint logging capabilities. This includes using additional process-level logging, such as Sysmon and PowerShell logging, to enhance log detection coverage.

Evolving Tactics

The SLOW#TEMPEST campaign highlights cybercriminals’ evolving tactics. They are increasingly targeting specific regions and industries with tailored attacks. The campaign’s ability to remain undetected for weeks underscores the importance of robust cybersecurity measures, particularly in sectors that are likely to be targeted by such sophisticated operations.

The Securonix Threat Research team says it will continue to monitor the situation and advises entities to remain vigilant against similar attacks.

ISB Staff Reporter
  • ISB Staff Reporter
    Mass Exploit Lets Attackers Install Plugins Arbitrarily
  • ISB Staff Reporter
    Cyberattacks Soar 47% Globally – Attacks on Education Increase by 73%
  • ISB Staff Reporter
    CISA Warns of Two Known Exploited Vulnerabilities
  • ISB Staff Reporter
    JFrog Becomes an AI System of Record, Debuts JFrog ML

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Dutch police, NCSC take down major botnet

June 4, 20264 Mins Read

CrowdStrike, Google, and Shadowserver Foundation disrupt Glassworm botnet

June 1, 20265 Mins Read

Threat Actors Deploy Tiflux RMM for Persistent Remote Access

May 29, 20263 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}