Microsoft Dismantles “Fox Tempest” Code-Signing Network Fueling Global Ransomware
ID: 7315a00f-64ec-540a-b205-9ce936803006
STIX ID: report--7315a00f-64ec-540a-b205-9ce936803006
Feed Name: securityonline.info
Threat Score
Microsoft and partner Resecurity disrupted 'Fox Tempest', a criminal operation offering malware-signing-as-a-service by abusing Microsoft Artifact Signing to create 72-hour fraudulent code-signing certificates; these signed binaries enabled distribution of malware (including Oyster, Lumma, Vidar) and deployment of Rhysida ransomware across multiple sectors before Microsoft revoked over a thousand fraudulent certificates and disabled core infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
