Fox Tempest Linked to Malware-Signing Service Abusing Microsoft Artifact Signing
ID: 19a8df08-77b7-584d-8b1a-90ba1ff68459
STIX ID: report--19a8df08-77b7-584d-8b1a-90ba1ff68459
Feed Name: GBHackers
Fox Tempest ran a commercial malware-signing-as-a-service that abused Microsoft’s Artifact Signing platform to produce short-lived, legitimate-looking code-signing certificates for criminals, enabling distribution of signed malware (including ransomware and info-stealers) across healthcare, education, government, finance and other sectors; Microsoft and partners disrupted the operation in May 2026 after identifying over 1,000 certificates, hundreds of Azure tenants, multiple linked threat groups and indicators, and provided detection and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
