logo

Microsoft Disrupts Ransomware Campaign Abusing Azure Certificates

ID: 0d25a46b-070e-52c2-883a-766030b25096

STIX ID: report--0d25a46b-070e-52c2-883a-766030b25096

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-10-17

Date Updated: 2026-04-21

Author: Rob Wright

...
...

**Microsoft disrupted a Rhysida ransomware campaign by Vanilla Tempest that used SEO-poisoned sites hosting fake MSTeamsSetup.exe installers signed with valid code-signing certificates (including >200 from Azure Trusted Signing) to drop the Oyster backdoor and deploy Rhysida; attackers also used certificates from DigiCert, GlobalSign, and SSL.com and mimicked Microsoft Teams domains to evade detection.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.