logo

Fake malware-signing service Fox Tempest dismantled by Microsoft

ID: c025ff15-f10a-5143-ac32-6edce41c1227

STIX ID: report--c025ff15-f10a-5143-ac32-6edce41c1227

Feed Name: Malwarebytes Blog

Threat Score
75/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

...
...

Microsoft disrupted a malware-signing-as-a-service called Fox Tempest that offered cybercriminal customers the ability to upload malicious binaries and receive them back digitally signed with short-lived Microsoft-issued certificates (valid ~72 hours). By abusing these trusted-looking certificates, actors distributed ransomware and infostealers—masquerading installers as legitimate software like AnyDesk or Teams—allowing malware to bypass reputation-based controls and impact multiple sectors including healthcare, education, government, and finance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.