Vanilla Tempest is a apt_group tracked across 6 threat clusters and 10 intelligence report mentions on ThreatCluster. First observed October 31, 2025; most recent activity May 20, 2026.
The provided articles describe campaigns involving a loader-based intrusion chain (Gootloader) used to deliver ransomware payloads such as Rhysida. While Vanilla Tempest is not explicitly named in the articles, the activity fits loader-first APT-style campaigns that deploy ransomware via deceptive Microsoft Teams ads and similar user-targeted tricks, highlighting evolving delivery techniques and ransomware impact.
On May 19, 2026, Microsoft disrupted Fox Tempest, a malware-signing-as-a-service (MSaaS) operation that provided over 1,000 fraudulent code-signing certificates to cybercriminals, enabling them to disguise malware as…
Gootloader malware, known for delivering ransomware, has re-emerged after reduced activity, with Huntress reporting three infections since October 27, 2025. Two of these incidents resulted in hands-on-keyboard…
Gootloader malware has re-emerged after a period of reduced activity, with Huntress reporting three infections since October 27, 2025. Two of these incidents resulted in hands-on-keyboard intrusions, leading to domain…
GootLoader malware utilizes malformed ZIP files composed of concatenated archives to bypass security measures. This technique has been linked to ransomware operations, including Vanilla Tempest, and is designed to evade…
The Rhysida ransomware group is exploiting fake advertisements for Microsoft Teams to distribute malware, specifically targeting users searching for the software. This campaign employs malvertising techniques,…
The Rhysida ransomware gang is exploiting fake ads for Microsoft Teams to distribute malware. Users searching for Microsoft Teams may encounter these deceptive links, which lead to data exfiltration or encryption…