logo

Microsoft disrupts Fox Tempest malware-signing-as-a-service platform tied to ransomware gangs

ID: ab9f7baf-fa9e-5ccf-8e11-09498ae31f5e

STIX ID: report--ab9f7baf-fa9e-5ccf-8e11-09498ae31f5e

Feed Name: The Record from Recorded Future News

Threat Score
78/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

...
...

Microsoft disrupted 'Fox Tempest', a well-resourced malware-signing-as-a-service (MSaaS) that weaponized Microsoft Artifact Signing to generate short-lived fraudulent code-signing certificates, enabling ransomware affiliates and malware operators to make malicious binaries appear legitimate; Microsoft seized the site, revoked over 1,000 certificates, took down hundreds of supporting virtual machines and Azure tenants, and found evidence of wide use by ransomware groups and infostealer families across multiple countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.