logo

Microsoft disrupts cybercrime service offering malware disguised as legitimate software

ID: 38c38a86-3612-5163-94d9-e32b847e4a6c

STIX ID: report--38c38a86-3612-5163-94d9-e32b847e4a6c

Feed Name: Nextgov Cybersecurity

Threat Score
78/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: David DiMolfetta

...
...

Microsoft seized infrastructure and legal action against "Fox Tempest," a malware-signing-as-a-service that abused Microsoft code-signing tools to provide valid-looking signatures for malicious software. The service, active since May of last year and used by ransomware and other criminal actors (Microsoft also named "Vanilla Tempest" as a co-conspirator), enabled attacks across healthcare, education, government, and financial sectors in multiple countries before Microsoft disrupted the operation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.