logo

Exposing Fox Tempest: A malware-signing service operation

ID: abe6606c-c9f9-50d4-8c80-3bb56c9fc377

STIX ID: report--abe6606c-c9f9-50d4-8c80-3bb56c9fc377

Feed Name: Microsoft Security

Threat Score
78/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Microsoft Threat Intelligence

...
...

Microsoft Threat Intelligence describes Fox Tempest, an MSaaS operator that abused Microsoft Artifact Signing to create short-lived legitimate-looking code-signing certificates used by other criminals to deliver signed malware and ransomware globally; the report documents operational details, linkage to downstream ransomware groups (e.g., Vanilla Tempest, Rhysida), IOCs (domains, certificate hashes, file hashes), and mitigation/detection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.