Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Sandworm Uses Fake Job Interviews to Distribute Trojanized WireGuard VPN
August 12, 2026
New Phishing Campaign Impersonates Google, Delivers Fake Audio Message
August 12, 2026
Best Business VPN Solutions for 2026
August 12, 2026
Home/CyberSecurity News/Fox Tempest Abused Microsoft Artifact Signing to Certify Malware
CyberSecurity News

Fox Tempest Abused Microsoft Artifact Signing to Certify Malware

Key Takeaways The Fox Tempest threat actor operated a “malware-signing-as-a-service” (MSaaS) platform, enabling cybercriminals to sign malicious code with legitimate-looking Microsoft...

Sarah simpson
Sarah simpson
May 20, 2026 4 Min Read
63 0

Key Takeaways

  • The Fox Tempest threat actor operated a “malware-signing-as-a-service” (MSaaS) platform, enabling cybercriminals to sign malicious code with legitimate-looking Microsoft digital certificates.
  • This service leveraged Microsoft’s Artifact Signing infrastructure (formerly Azure Trusted Signing) to generate short-lived code-signing certificates, which were then used to sign malware, making it appear trusted.
  • In May 2026, Microsoft’s Digital Crimes Unit (DCU), in collaboration with Resecurity, successfully disrupted Fox Tempest’s operations, revoking over 1,000 fraudulent certificates.
  • Fox Tempest’s service was linked to major ransomware groups and information stealers, including Rhysida, Qilin, Akira, and Lumma Stealer.

A sophisticated financially motivated threat actor known as Fox Tempest ran a “malware-signing-as-a-service” (MSaaS) platform that exploited Microsoft’s Artifact Signing infrastructure. This allowed the group to produce valid digital signatures for malicious software, enabling cybercriminals to circumvent security measures and disseminate malware that appeared to be legitimate.

Table Of Content

  • Key Takeaways
  • Abuse of Microsoft Artifact Signing
  • Impact and Reach
  • Indicators of Compromise (IOCs)
  • What You Should Do

In a significant crackdown in May 2026, the Microsoft Digital Crimes Unit (DCU), working alongside Resecurity, dismantled Fox Tempest’s infrastructure. This operation led to the revocation of more than 1,000 fraudulent certificates associated with the illicit service.

Abuse of Microsoft Artifact Signing

Fox Tempest exploited Microsoft’s Artifact Signing service, previously known as Azure Trusted Signing, to acquire code-signing certificates that remained valid for up to 72 hours. These temporary certificates were then used by attackers to sign malware binaries, making them resemble trusted applications. The malicious software often mimicked legitimate programs such as Microsoft Teams, AnyDesk, PuTTY, and Webex.

To obtain these certificates, the threat actors are believed to have used stolen or fabricated identities from the United States and Canada, successfully passing Microsoft’s identity verification protocols. The entire operation was facilitated through a platform called signspace[.]cloud, which is now defunct. This platform offered a user interface where customers could upload their malicious files and receive digitally signed binaries in return.

Microsoft Threat Intelligence had been monitoring Fox Tempest since September 2025, identifying it as a crucial enabler within the broader ransomware ecosystem rather than a direct perpetrator of attacks. The group established hundreds of Azure tenants and subscriptions to support its activities, issuing thousands of certificates at scale.

By early 2026, Fox Tempest refined its operational methods by providing pre-configured virtual machines (VMs) hosted on various third-party providers. These VMs allowed customers to upload their payloads directly into controlled environments. Automated scripts and configuration files, such as metadata.json and PowerShell scripts, were then used to efficiently sign the malware. This strategic shift enhanced the group’s operational security and streamlined the signing process.

Impact and Reach

The MSaaS platform operated by Fox Tempest has been linked to numerous prominent threat actors and ransomware families. Groups like Vanilla Tempest, Storm-0501, Storm-2561, and Storm-0249 have utilized malware signed by Fox Tempest in actual intrusions. The associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.

One notable attack chain involved trojanized Microsoft Teams installers disseminated through malvertising. Victims who downloaded these fake installers would execute a signed binary that subsequently deployed the Oyster backdoor. This backdoor facilitated persistence, command-and-control (C2) communications, and ultimately, the deployment of ransomware.

Cryptocurrency analysis has revealed that Fox Tempest maintains close ties with ransomware affiliates linked to families such as Qilin, Akira, and INC, generating revenues in the millions of dollars. Fox Tempest operated as a commercial service, charging cybercriminals between $5,000 and $9,000 for its malware-signing services. Access to the service was managed through Telegram channels and online forms, with priority given to higher-paying customers. This service significantly lowered the entry barrier for less sophisticated threat actors by providing on-demand access to trusted code-signing capabilities.

Indicators of Compromise (IOCs)

Key Indicators of Compromise (IOCs) associated with Fox Tempest activities include the domain signspace[.]cloud. Investigators also identified the following SHA-1 certificate fingerprints:

  • dc0acb01e3086ea8a9cb144a5f97810d291020ce
  • 7e6d9dac619c04ae1b3c8c0906123e752ed66d63

Additionally, the following SHA-256 file hashes have been linked to the campaign:

  • f0668ce925f36ff7f3359b0ea47e3fa243af13cd6ad9661dfccc9ff79fb4f1cc
  • 11af4566539ad3224e968194c7a9ad7b596460d8f6e423fc62d1ea5fc0724326

What You Should Do

Microsoft’s report emphasizes that organizations can mitigate exposure to signed malware abuse by implementing several key security controls:

  • Activate cloud-delivered protection and real-time scanning features within your endpoint security solutions.
  • Deploy Microsoft Defender SmartScreen to effectively block malicious downloads and access to harmful websites.
  • Enforce tamper protection to prevent unauthorized disabling or modification of security tools.
  • Utilize attack surface reduction (ASR) rules to obstruct common malware techniques and behaviors.
  • Enable Safe Links and Safe Attachments functionalities in your email security solutions to protect against phishing and malicious content.
  • Proactively monitor for any suspicious certificate usage and instances of short-lived signing activity within your environment.

The successful takedown of Fox Tempest’s infrastructure by Microsoft represents a significant disruption to the cybercrime supply chain. By targeting the enabling service itself rather than individual attackers, this operation aims to diminish the capacity of numerous ransomware groups to distribute trusted malware at scale. However, the incident underscores the ongoing challenge of legitimate cloud services and trust mechanisms being exploited, highlighting the critical need for more robust identity validation and continuous certificate monitoring across the entire digital ecosystem.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareransomwareSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

GitHub Employee Device Hack Exposes Internal Repositories

Next Post

Critical NGINX Vulnerability CVE-2024-35200 Lets Attackers Inject Malicious Code

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Microsoft SharePoint Server CVE-2023-29357 Lets Attackers Remotely Execute Code
August 12, 2026
Critical Windows AFD.sys Zero-Day Exploited by Lazarus Group
August 12, 2026
Critical Microsoft Outlook RCE Vulnerability Patched
August 12, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us