logo

Microsoft dismantled malware-signing network Fox Tempest

ID: 21529d20-bb71-5b2e-8169-b814ab52c8b7

STIX ID: report--21529d20-bb71-5b2e-8169-b814ab52c8b7

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Pierluigi Paganini

...
...

Microsoft dismantled Fox Tempest, a commercialized malware-signing-as-a-service that issued over 1,000 short‑lived Microsoft Artifact Signing certificates and supported distribution of ransomware and infostealers (including Rhysida, Oyster, Lumma Stealer, Vidar); Microsoft seized infrastructure, revoked certificates, filed suit, and is coordinating with industry and law enforcement to disrupt the operation and mitigate downstream impacts across multiple sectors and countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.