logo

Resecurity Supports Microsoft DCU in Disrupting Fox Tempest ’s Cybercriminal Code-Signing Ecosystem

ID: 17dce722-fcad-5c88-bfb9-ff29895a9a8f

STIX ID: report--17dce722-fcad-5c88-bfb9-ff29895a9a8f

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-05-28

Date Updated: 2026-05-29

Author: Pierluigi Paganini

...
...

Microsoft, supported by Resecurity, disrupted Fox Tempest—a commercial malware-signing service that abused Microsoft Artifact Signing to provide fraudulent code-signing certificates to cybercriminals—by seizing the signspace.cloud site, taking hundreds of virtual machines offline, blocking hosting infrastructure, and revoking more than 1,000 certificates; Microsoft linked the operation to multiple ransomware and malware families, illustrating the high impact of degrading upstream code-signing ecosystems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.