Fox Tempest takedown hits ransomware supply chain

Microsoft has disrupted infrastructure used by Fox Tempest, a cybercrime-enabling group accused of selling fraudulent code-signing services that helped ransomware operators disguise malware as trusted software.

The action, led by Microsoft’s Digital Crimes Unit, targeted a malware-signing-as-a-service operation that allegedly abused legitimate software verification systems, including Microsoft’s Artifact Signing platform. A legal case unsealed in the US District Court for the Southern District of New York said the service had enabled attackers since May 2025 to make malicious files appear authentic, lowering the chance that security tools or users would block them.

The takedown included seizure of the group’s website, signspace[.]cloud, disruption of related domain and cloud infrastructure, removal of hundreds of virtual machines, and blocking of a site hosting underlying code. Microsoft said it also deleted or evicted more than 1,000 accounts and subscriptions connected to the operation, while continuing to revoke fraudulently obtained certificates and strengthen verification controls.

Fox Tempest’s alleged business model reflects a sharper shift in cybercrime, where specialist providers sell discrete services to ransomware crews rather than carrying out attacks from start to finish. Such services allow criminals to purchase access, malware, infrastructure, phishing kits, evasion tools and signing capability from different vendors, then assemble attacks with greater speed and lower technical barriers.

Code signing is intended to help users and security systems verify that software comes from a trusted publisher and has not been tampered with. Fox Tempest allegedly turned that trust mechanism into an entry point for abuse. Customers could upload malicious files to an online portal, obtain signatures using Fox Tempest-controlled certificates, and distribute malware through search manipulation, malicious advertising or fake download pages.

The operation is believed to have generated more than 1,000 certificates and millions of dollars in proceeds. Cybercriminal customers allegedly paid thousands of dollars for the service, with some offerings priced between $5,000 and $9,500, depending on access speed and volume. Investigators found that operators used fabricated identities and impersonated legitimate organisations to secure code-signing credentials at scale.

Malware signed through the service was linked to ransomware and criminal groups including Vanilla Tempest, Rhysida, Akira, Qilin and INC, as well as malware families such as Oyster, Lumma Stealer and Vidar. Vanilla Tempest was named as a co-conspirator in the case and has been associated with attacks against schools, hospitals and other critical organisations.

The group’s reach extended across several major economies, with victims and targets identified in the United States, France, India, China, Brazil, Germany, Japan, the United Kingdom, Italy and Spain. The affected sectors included healthcare, education, government and financial services, all of which remain frequent targets because operational disruption can increase pressure to pay extortion demands.

The case also builds on an earlier Microsoft action against Vanilla Tempest, when more than 200 certificates were revoked after they were used to sign fake Microsoft Teams installers. Those files delivered the Oyster backdoor and were tied to Rhysida ransomware deployment, underscoring how trusted-looking installers can give attackers a route into corporate networks.

The Fox Tempest disruption was coordinated with law enforcement and private-sector partners, including the FBI, Europol’s European Cybercrime Centre and cybersecurity firm Resecurity. The cooperation points to a growing enforcement strategy aimed not only at ransomware crews but also at the suppliers that make attacks more scalable.

Cybersecurity specialists have long warned that certificate abuse is difficult to contain because it exploits a foundation of software trust. Once malware is signed, it may pass checks that would otherwise flag an unknown or suspicious file. That does not make the software safe, but it can weaken barriers that protect users from opening infected downloads.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in:
Global condemnation widens over deadly Saudi airport strikes // OpenAI extends GPT-6 access with interactive ChatGPT interface // LANDMARK Launches ‘Destination CENTRAL’: A District-Wide Invitation to Explore the Dynamism, Luxury, and Soul of Central // Malicious GitHub workflows expose credentials across hundreds of repositories // Oriental Residence Bangkok Awarded One MICHELIN Key for the Third Consecutive Year // India establishes 5.56 km open-air quantum security link // First Week Of Anti-CEC Agitation Turns Into Electoral Rights Movement // Gold reaches weekly peak as oil prices retreat // India rebuts Musk allegations over Starlink launch delay // UK and allies expose Integrity Tech cyber operations // Prudential Singapore launches multi-generational protection plan to help caregivers manage families’ healthcare needs // Bypoll Results In Bengal And Assam Underline BJP’s Expansion In Eastern Region // Abu Dhabi launches AI training to accelerate government transformation // Almarai earmarks $4 billion for expansion through 2031 // Trump-Newsom Clash Assumes Special Significance Before Nov 3 Polls // Abu Dhabi climate summit records over 1,000 registrations // Two Bypoll Results In Bengal Vindicate State BJP’s Success In Courting Minorities // OPPO Find X10 Pro Max to Debut Globally with MediaTek’s 2nm Flagship Dimensity 9600 Pro // UAE delegation heads to Bangkok for IMF meetings // Ping An Digital Bank Becomes Hong Kong’s First Digital Bank to Enter High-End Wealth Management Segment //