Microsoft dismantled malware-signing network Fox Tempest
ID: 21529d20-bb71-5b2e-8169-b814ab52c8b7
STIX ID: report--21529d20-bb71-5b2e-8169-b814ab52c8b7
Feed Name: Security Affairs
Threat Score
Microsoft dismantled Fox Tempest, a commercialized malware-signing-as-a-service that issued over 1,000 short‑lived Microsoft Artifact Signing certificates and supported distribution of ransomware and infostealers (including Rhysida, Oyster, Lumma Stealer, Vidar); Microsoft seized infrastructure, revoked certificates, filed suit, and is coordinating with industry and law enforcement to disrupt the operation and mitigate downstream impacts across multiple sectors and countries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
