logo

Microsoft Takes Down Fox Tempest for Providing Ransomware-Enabling Signing Tool

ID: 3023eeef-890b-5086-95b7-cdf1c394e341

STIX ID: report--3023eeef-890b-5086-95b7-cdf1c394e341

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

...
...

Microsoft’s Digital Crimes Unit exposed and disrupted Fox Tempest, a criminal group running a "malware-signing-as-a-service" that fraudulently signed malware and enabled ransomware and infostealer campaigns (including Rhysida/Vanilla Tempest and strains like Lumma Stealer, Vidar, Oyster); the report describes the group’s abuse of legitimate code-signing systems, the global scope of affected hosts, and coordinated takedown actions with providers and law enforcement that disabled infrastructure, sinkholed domains, and reduced illicit certificate issuance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.