logo

Microsoft Dismantles “Fox Tempest” Code-Signing Network Fueling Global Ransomware

ID: 7315a00f-64ec-540a-b205-9ce936803006

STIX ID: report--7315a00f-64ec-540a-b205-9ce936803006

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-05-25

Date Updated: 2026-05-25

Author: Ddos

...
...

Microsoft and partner Resecurity disrupted 'Fox Tempest', a criminal operation offering malware-signing-as-a-service by abusing Microsoft Artifact Signing to create 72-hour fraudulent code-signing certificates; these signed binaries enabled distribution of malware (including Oyster, Lumma, Vidar) and deployment of Rhysida ransomware across multiple sectors before Microsoft revoked over a thousand fraudulent certificates and disabled core infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.