Microsoft shuts down illegal code-signing operation used by ransomware crims to mask their malware
ID: 1bdc96af-7d78-5233-bcbc-0b74989ca076
STIX ID: report--1bdc96af-7d78-5233-bcbc-0b74989ca076
Feed Name: The Register (Security)
Microsoft shut down ‘Fox Tempest’, an illicit code-signing-as-a-service that abused Microsoft Artifact Signing by creating fraudulent tenant accounts to obtain and sell legitimate code-signing certificates to ransomware and malware operators. Customers included known ransomware affiliates (e.g., Vanilla Tempest) that used the certificates to sign malware such as Oyster, Lumma, Vidar, and Rhysida, contributing to infections of thousands of US machines — including systems owned by Microsoft; the Digital Crimes Unit documented purchases, pricing ($5,000–$9,500), and cryptocurrency wallets and has pursued legal action.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
