logo

Microsoft Disrupts Malware-Signing Service Used by Ransomware Gangs

ID: 0009ee21-bca0-5f1b-8bc6-25bd75d1b9d2

STIX ID: report--0009ee21-bca0-5f1b-8bc6-25bd75d1b9d2

Feed Name: TechRepublic Security

Threat Score
78/100

Date Published: 2026-05-20

Date Updated: 2026-05-21

Author: Ken Underhill

...
...

Microsoft disrupted Fox Tempest, a commercial malware-signing-as-a-service that abused Azure Artifact Signing to issue fraudulent short-lived code-signing certificates and sign malware (including Oyster, Lumma Stealer, Vidar) used by multiple ransomware groups (Rhysida, Akira, INC, Qilin, BlackByte). The service provided hosted signing infrastructure, accepted uploaded malware, and was monetized publicly, demonstrating large-scale criminal organization; organizations are advised to strengthen identity verification, certificate monitoring, allowlisting, and infrastructure segmentation to mitigate trusted-signature abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.