Activity timeline
Vanilla Tempest appears in 3 tracked threats between and ; the busiest month was 2026-06 with 1 report.
ATT&CK techniques observed
- T1053.005 Scheduled Task — Persistenceobserved in 2 of 3 tracked threats
- T1059.001 PowerShell — Executionobserved in 2 of 3 tracked threats
- T1059.003 Windows Command Shell — Executionobserved in 2 of 3 tracked threats
- T1069.002 Domain Groups — Discoveryobserved in 2 of 3 tracked threats
- T1087.002 Account Discovery: Domain Account — Discoveryobserved in 2 of 3 tracked threats
- T1102.001 Dead Drop Resolver — Command and Controlobserved in 2 of 3 tracked threats
- T1218.007 Msiexec — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
- T1482 Domain Trust Discovery — Discoveryobserved in 2 of 3 tracked threats
- T1547.001 Registry Run Keys / Startup Folder — Persistenceobserved in 2 of 3 tracked threats
- T1553.002 Code Signing — Defense Impairmentobserved in 2 of 3 tracked threats
- T1574.001 DLL — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
- T1583.006 Acquire Infrastructure: Web Services — Resource Developmentobserved in 2 of 3 tracked threats
- T1588.002 Tool — Resource Developmentobserved in 2 of 3 tracked threats
- T1001.002 Steganography — Command and Controlobserved in 1 of 3 tracked threats
- T1003.003 NTDS — Credential Accessobserved in 1 of 3 tracked threats
Tracked threats
- Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)CRITICAL
- ClickFix Cluster Uses DLL Sideloading and Compromised WordPress Sites to Deliver Lorem Ipsum Loader, Linked to Vanilla TempestHIGH
- Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via SEO-Poisoned Trojanized Microsoft Teams InstallersHIGH