惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

GbyAI
GbyAI
Martin Fowler
Martin Fowler
云风的 BLOG
云风的 BLOG
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
T
The Blog of Author Tim Ferriss
大猫的无限游戏
大猫的无限游戏
A
About on SuperTechFans
小众软件
小众软件
博客园_首页
博客园 - 聂微东
罗磊的独立博客
Recent Announcements
Recent Announcements
U
Unit 42
N
Netflix TechBlog - Medium
Blog — PlanetScale
Blog — PlanetScale
阮一峰的网络日志
阮一峰的网络日志
博客园 - 叶小钗
V
V2EX
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
IT之家
IT之家
Stack Overflow Blog
Stack Overflow Blog
博客园 - Franky
D
DataBreaches.Net
Last Week in AI
Last Week in AI

Security Affairs

Carding service Jerry’s Store leak exposes 345,000 stolen payment cards Anthropic launches Claude Security to counter rapid AI-Powered exploits SonicWall patches three SonicOS flaws in Gen 6, 7 and 8 firewalls. Patch them now Copy Fail: New Linux bug enables Root via page‑cache corruption Agent’s claims on WhatsApp access spark security concerns Meta accused of violating DSA by failing to safeguard minors Large-scale Roblox hacking operation shut down by Ukrainian authorities CVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosure Internet censorship index reveals Russia’s lead and widespread content blocking All supported cPanel versions hit by critical auth bug, now patched U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog ShinyHunters exploit Anodot incident to target Vimeo CVE-2026-3854 GitHub flaw enables remote code execution Signal Phishing Campaign Targets German Officials in Suspected Russian Operation Microsoft fixes Entra ID flaw enabling privilege escalation New Android spyware Morpheus linked to Italian surveillance firm NCSC launches SilentGlass, a plug-in device to secure HDMI and DisplayPort links Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software LINKEDIN BROWSERGATE Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting Fast16: Pre-Stuxnet malware that targeted precision engineering software Italy moves to extradite Chinese national to the U.S. over hacking charges U.S. utility giant Itron discloses a security breach Critical bug in CrowdStrike LogScale let attackers access files GopherWhisper: new China-linked APT targets Mongolia with Go-based malware SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 94 Trigona ransomware adopts custom tool to steal data and evade detection Security Affairs newsletter Round 574 by Pierluigi Paganini – INTERNATIONAL EDITION U.S. CISA adds SimpleHelp, Samsung, and D-Link flaws to its Known Exploited Vulnerabilities catalog
Microsoft dismantled malware-signing network Fox Tempest
Pierluigi Pa · 2026-05-20 · via Security Affairs

Microsoft disrupted Fox Tempest, a malware-signing-as-a-service (MSaaS) that allowed attackers to sign malware with fake trusted certificates.

Microsoft said it disrupted a cybercrime operation run by a threat actor named Fox Tempest, which helped threat actors sign malware with short-lived certificates to make malicious software appear legitimate. The service abused Microsoft Artifact Signing and supported ransomware and malware campaigns.

Microsoft seized the infrastructure the group was running on, pulled the fraudulent accounts, and tightened up the verification processes that had been abused. It also filed a lawsuit against Fox Tempest and Vanilla Tempest, a legal move that in these kinds of operations does real practical work: it gives Microsoft the grounds to seize domains, tear down server infrastructure, and push third-party providers to pull the plug on whatever is still running.

Microsoft said Fox Tempest created over 1,000 certificates and set up hundreds of Azure tenants and subscriptions to support its malware-signing-as-a-service operation. The IT giant revoked more than 1,000 code-signing certificates linked to the group.

In May 2026, Microsoft’s Digital Crimes Unit, with industry partners, dismantled Fox Tempest’s infrastructure. The service had been used to sign and distribute malware, including Rhysida ransomware, Oyster, Lumma Stealer, and Vidar, making malicious software appear legitimate and easier to deliver at scale.

Microsoft Threat Intelligence researchers pointed out that Fox Tempest does not directly attack victims but instead provides infrastructure and services that support ransomware groups. Since September 2025, it has been linked to operators like Vanilla Tempest, Storm-0501Storm-2561, and Storm-0249, which used Fox Tempest-signed malware in real attacks delivered through malvertising, SEO poisoning, and fake ads.

The group is also tied to ransomware affiliates behind families such as INC, Qilin, and Akira, with millions in alleged proceeds.

“Based on the scale of the MSaaS offering, Microsoft Threat Intelligence assesses that Fox Tempest is a well-resourced group handling infrastructure creation, customer relations, and financial transactions.” states Microsoft. “The downstream impact of these operations has resulted in attacks against a broad range of industry sectors, including healthcare, education, government, and financial services, impacting organizations globally including, but not limited to the United States, France, India, and China.”

Fox Tempest operated a malware-signing-as-a-service platform called signspace[.]cloud, disrupted by its Microsoft experts at the Digital Crimes Unit. The service allowed threat actors to obtain short-lived (72-hour) Microsoft-issued certificates via Artifact Signing, enabling malicious files to appear legitimate and bypass security controls.

To obtain certificates, users had to pass identity verification, suggesting the likely use of stolen identities. The platform included admin and customer portals where malicious files were uploaded and signed, with infrastructure built on Azure and linked to a GitHub repository named code-signing-service.

Fox Tempest

In February 2026, Fox Tempest evolved its operation by providing pre-configured virtual machines hosted on third-party infrastructure, letting customers directly submit malware for signing. This reduced friction and improved scalability, further enabling the distribution of trusted but malicious binaries. Microsoft said it disrupted this infrastructure and continues to work with partners to counter similar abuse.

Fox Tempest monetized its malware-signing-as-a-service by charging thousands of dollars for access. Customers chose plans between $5,000 and $9,000, with higher tiers getting priority access and virtual machines for signing malicious code with trusted certificates.

Fox Tempest didn’t just build the tool and walk away. The operation was actively run on Telegram, where channels advertised EV certificate access and buyers coordinated payments. Rather than a hidden underground network, it functioned more like a service with a clear customer base, managed through a small set of accounts and shared infrastructure. This centralized setup made it possible to sign malware at scale while keeping operations relatively streamlined and repeatable.

Microsoft recommends layered defenses against Fox Tempest attacks, including cloud protection, Safe Links/Attachments, SmartScreen, and strong identity controls. Key steps also include tamper protection, limiting admin rights, and enabling attack surface reduction rules.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Fox Tempest)