Activity timeline
Periwinkle Tempest appears in 5 tracked threats between and ; the busiest month was 2026-07 with 4 reports.
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 5 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 4 of 5 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 4 of 5 tracked threats
- T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 5 tracked threats
- T1016 System Network Configuration Discovery — Discoveryobserved in 3 of 5 tracked threats
- T1021 Remote Services — Lateral Movementobserved in 3 of 5 tracked threats
- T1053 Scheduled Task/Job — Persistenceobserved in 3 of 5 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 3 of 5 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 3 of 5 tracked threats
- T1106 Native API — Executionobserved in 3 of 5 tracked threats
- T1572 Protocol Tunneling — Command and Controlobserved in 3 of 5 tracked threats
- T1003 OS Credential Dumping — Credential Accessobserved in 2 of 5 tracked threats
- T1008 Fallback Channels — Command and Controlobserved in 2 of 5 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 2 of 5 tracked threats
- T1053.005 Scheduled Task — Persistenceobserved in 2 of 5 tracked threats
Tracked threats
- TrickBot injectDLL Module: Man-in-the-Browser Web Injection Against Certificate TransparencyHIGH
- TrickBot Banking Trojan (Anchor_DNS) Uses DNS Tunneling Over westurn.in for Covert C2HIGH
- TrickBot Malware Variant Adopts DNS Tunneling for C2 Communications (westurn.in)HIGH
- SystemBC (Coroxy / DroxiDat) Malware: Multi-Purpose SOCKS5/Tor Proxy Backdoor Enabling Ransomware OperationsHIGH
- Armenian National Karen Vardanyan Pleads Guilty to Ryuk Ransomware Conspiracy (District of Oregon)HIGH