Fox Tempest Abused Microsoft Artifact Signing to Certify Malware
Key Takeaways The Fox Tempest threat actor operated a “malware-signing-as-a-service” (MSaaS) platform, enabling cybercriminals to sign malicious code with legitimate-looking Microsoft...
Key Takeaways
- The Fox Tempest threat actor operated a “malware-signing-as-a-service” (MSaaS) platform, enabling cybercriminals to sign malicious code with legitimate-looking Microsoft digital certificates.
- This service leveraged Microsoft’s Artifact Signing infrastructure (formerly Azure Trusted Signing) to generate short-lived code-signing certificates, which were then used to sign malware, making it appear trusted.
- In May 2026, Microsoft’s Digital Crimes Unit (DCU), in collaboration with Resecurity, successfully disrupted Fox Tempest’s operations, revoking over 1,000 fraudulent certificates.
- Fox Tempest’s service was linked to major ransomware groups and information stealers, including Rhysida, Qilin, Akira, and Lumma Stealer.
A sophisticated financially motivated threat actor known as Fox Tempest ran a “malware-signing-as-a-service” (MSaaS) platform that exploited Microsoft’s Artifact Signing infrastructure. This allowed the group to produce valid digital signatures for malicious software, enabling cybercriminals to circumvent security measures and disseminate malware that appeared to be legitimate.
Table Of Content
In a significant crackdown in May 2026, the Microsoft Digital Crimes Unit (DCU), working alongside Resecurity, dismantled Fox Tempest’s infrastructure. This operation led to the revocation of more than 1,000 fraudulent certificates associated with the illicit service.
Abuse of Microsoft Artifact Signing
Fox Tempest exploited Microsoft’s Artifact Signing service, previously known as Azure Trusted Signing, to acquire code-signing certificates that remained valid for up to 72 hours. These temporary certificates were then used by attackers to sign malware binaries, making them resemble trusted applications. The malicious software often mimicked legitimate programs such as Microsoft Teams, AnyDesk, PuTTY, and Webex.
To obtain these certificates, the threat actors are believed to have used stolen or fabricated identities from the United States and Canada, successfully passing Microsoft’s identity verification protocols. The entire operation was facilitated through a platform called signspace[.]cloud, which is now defunct. This platform offered a user interface where customers could upload their malicious files and receive digitally signed binaries in return.
Microsoft Threat Intelligence had been monitoring Fox Tempest since September 2025, identifying it as a crucial enabler within the broader ransomware ecosystem rather than a direct perpetrator of attacks. The group established hundreds of Azure tenants and subscriptions to support its activities, issuing thousands of certificates at scale.
By early 2026, Fox Tempest refined its operational methods by providing pre-configured virtual machines (VMs) hosted on various third-party providers. These VMs allowed customers to upload their payloads directly into controlled environments. Automated scripts and configuration files, such as metadata.json and PowerShell scripts, were then used to efficiently sign the malware. This strategic shift enhanced the group’s operational security and streamlined the signing process.
Impact and Reach
The MSaaS platform operated by Fox Tempest has been linked to numerous prominent threat actors and ransomware families. Groups like Vanilla Tempest, Storm-0501, Storm-2561, and Storm-0249 have utilized malware signed by Fox Tempest in actual intrusions. The associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
One notable attack chain involved trojanized Microsoft Teams installers disseminated through malvertising. Victims who downloaded these fake installers would execute a signed binary that subsequently deployed the Oyster backdoor. This backdoor facilitated persistence, command-and-control (C2) communications, and ultimately, the deployment of ransomware.
Cryptocurrency analysis has revealed that Fox Tempest maintains close ties with ransomware affiliates linked to families such as Qilin, Akira, and INC, generating revenues in the millions of dollars. Fox Tempest operated as a commercial service, charging cybercriminals between $5,000 and $9,000 for its malware-signing services. Access to the service was managed through Telegram channels and online forms, with priority given to higher-paying customers. This service significantly lowered the entry barrier for less sophisticated threat actors by providing on-demand access to trusted code-signing capabilities.
Indicators of Compromise (IOCs)
Key Indicators of Compromise (IOCs) associated with Fox Tempest activities include the domain signspace[.]cloud. Investigators also identified the following SHA-1 certificate fingerprints:
dc0acb01e3086ea8a9cb144a5f97810d291020ce7e6d9dac619c04ae1b3c8c0906123e752ed66d63
Additionally, the following SHA-256 file hashes have been linked to the campaign:
f0668ce925f36ff7f3359b0ea47e3fa243af13cd6ad9661dfccc9ff79fb4f1cc11af4566539ad3224e968194c7a9ad7b596460d8f6e423fc62d1ea5fc0724326
What You Should Do
Microsoft’s report emphasizes that organizations can mitigate exposure to signed malware abuse by implementing several key security controls:
- Activate cloud-delivered protection and real-time scanning features within your endpoint security solutions.
- Deploy Microsoft Defender SmartScreen to effectively block malicious downloads and access to harmful websites.
- Enforce tamper protection to prevent unauthorized disabling or modification of security tools.
- Utilize attack surface reduction (ASR) rules to obstruct common malware techniques and behaviors.
- Enable Safe Links and Safe Attachments functionalities in your email security solutions to protect against phishing and malicious content.
- Proactively monitor for any suspicious certificate usage and instances of short-lived signing activity within your environment.
The successful takedown of Fox Tempest’s infrastructure by Microsoft represents a significant disruption to the cybercrime supply chain. By targeting the enabling service itself rather than individual attackers, this operation aims to diminish the capacity of numerous ransomware groups to distribute trusted malware at scale. However, the incident underscores the ongoing challenge of legitimate cloud services and trust mechanisms being exploited, highlighting the critical need for more robust identity validation and continuous certificate monitoring across the entire digital ecosystem.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.