logo

Cybercrime service disrupted for abusing Microsoft platform to sign malware

ID: 899aeeff-de95-55d1-99b5-17d6dda4d808

STIX ID: report--899aeeff-de95-55d1-99b5-17d6dda4d808

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Lawrence Abrams

...
...

Microsoft disrupted a criminal malware-signing-as-a-service (MSaaS) run by the actor dubbed Fox Tempest that abused Microsoft’s Artifact Signing platform to produce short-lived, fraudulently obtained code-signing certificates used to sign and legitimize malware and ransomware; the operation generated over 1,000 certificates, supported hundreds of Azure tenants, was tied to multiple malware and ransomware families (including Oyster, Lumma, Vidar, Rhysida and others), and has been the subject of legal action and infrastructure takedowns by Microsoft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.