Just in:
Dubai hotel provides free public co-working space // Venezuela defends sovereignty after Trump oil control claim // Trump rejects munitions fears as Iran clashes resume // Macao Economic, Trade and Tourism Investment Promotion Seminar Held in Singapore, Deepening Multi-Domain Cooperation to Empower Regional Growth // Inovatif Media Asia Sets Regional Ambitions in Motion with Tun Ahmad Fuzi as Strategic Advisor // InnoHK R&D Centres Establish Base at Science Park to Drive Emerging Industries and Pioneer Future Innovation // Amicura X1 Max Smart Cat Litter Box:AliExpress France Official Warehouse, Litter Box at One Click // SCX Corporation Accelerates SC Group’s Recurring-Income Businesses // Haldwani purification row: Caste back on political centre-stage // What Shein’s $27bn IPO means for Mubadala // Qatar economy contracts 7% as energy output slumps // Apical Provides Free Health Screenings and Treatment for Lubuk Gaung Residents // WisPaper Introduces TrueCite to Help Researchers Verify AI-Generated Academic References // India plans own orbital space outpost, second after China // US-Iran strikes revive confrontation across Hormuz and Jordan // Jungheinrich Marks 25 Years In Singapore, Leading APAC Strategic Hub And Electrification In The Market // Russia brings cryptocurrency market law into force // Adobe widens Saudi AI access with $4 billion programme // Apple raises evidence-destruction claims against OpenAI // Ingdan, Inc. (400.HK) Announces 2026 Interim Results //

Fox Tempest takedown hits ransomware supply chain

Microsoft has disrupted infrastructure used by Fox Tempest, a cybercrime-enabling group accused of selling fraudulent code-signing services that helped ransomware operators disguise malware as trusted software.

The action, led by Microsoft’s Digital Crimes Unit, targeted a malware-signing-as-a-service operation that allegedly abused legitimate software verification systems, including Microsoft’s Artifact Signing platform. A legal case unsealed in the US District Court for the Southern District of New York said the service had enabled attackers since May 2025 to make malicious files appear authentic, lowering the chance that security tools or users would block them.

The takedown included seizure of the group’s website, signspace[.]cloud, disruption of related domain and cloud infrastructure, removal of hundreds of virtual machines, and blocking of a site hosting underlying code. Microsoft said it also deleted or evicted more than 1,000 accounts and subscriptions connected to the operation, while continuing to revoke fraudulently obtained certificates and strengthen verification controls.

Fox Tempest’s alleged business model reflects a sharper shift in cybercrime, where specialist providers sell discrete services to ransomware crews rather than carrying out attacks from start to finish. Such services allow criminals to purchase access, malware, infrastructure, phishing kits, evasion tools and signing capability from different vendors, then assemble attacks with greater speed and lower technical barriers.

Code signing is intended to help users and security systems verify that software comes from a trusted publisher and has not been tampered with. Fox Tempest allegedly turned that trust mechanism into an entry point for abuse. Customers could upload malicious files to an online portal, obtain signatures using Fox Tempest-controlled certificates, and distribute malware through search manipulation, malicious advertising or fake download pages.

The operation is believed to have generated more than 1,000 certificates and millions of dollars in proceeds. Cybercriminal customers allegedly paid thousands of dollars for the service, with some offerings priced between $5,000 and $9,500, depending on access speed and volume. Investigators found that operators used fabricated identities and impersonated legitimate organisations to secure code-signing credentials at scale.

Malware signed through the service was linked to ransomware and criminal groups including Vanilla Tempest, Rhysida, Akira, Qilin and INC, as well as malware families such as Oyster, Lumma Stealer and Vidar. Vanilla Tempest was named as a co-conspirator in the case and has been associated with attacks against schools, hospitals and other critical organisations.

The group’s reach extended across several major economies, with victims and targets identified in the United States, France, India, China, Brazil, Germany, Japan, the United Kingdom, Italy and Spain. The affected sectors included healthcare, education, government and financial services, all of which remain frequent targets because operational disruption can increase pressure to pay extortion demands.

The case also builds on an earlier Microsoft action against Vanilla Tempest, when more than 200 certificates were revoked after they were used to sign fake Microsoft Teams installers. Those files delivered the Oyster backdoor and were tied to Rhysida ransomware deployment, underscoring how trusted-looking installers can give attackers a route into corporate networks.

The Fox Tempest disruption was coordinated with law enforcement and private-sector partners, including the FBI, Europol’s European Cybercrime Centre and cybersecurity firm Resecurity. The cooperation points to a growing enforcement strategy aimed not only at ransomware crews but also at the suppliers that make attacks more scalable.

Cybersecurity specialists have long warned that certificate abuse is difficult to contain because it exploits a foundation of software trust. Once malware is signed, it may pass checks that would otherwise flag an unknown or suspicious file. That does not make the software safe, but it can weaken barriers that protect users from opening infected downloads.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in:
Apple raises evidence-destruction claims against OpenAI // Best Mart 360 Reports Interim Revenue Growth to HK$1.45 billion // InnoHK R&D Centres Establish Base at Science Park to Drive Emerging Industries and Pioneer Future Innovation // Inovatif Media Asia Sets Regional Ambitions in Motion with Tun Ahmad Fuzi as Strategic Advisor // Chinese researchers engineer self-contracting muscle grafts // Dubai hotel provides free public co-working space // Qatar economy contracts 7% as energy output slumps // Hong Kong Science and Technology Parks Corporation Kicks Off 25th Anniversary Prelude “Innovation. Next by Nature.” // Gulf AI uptake outpaces measurable returns // Macao Economic, Trade and Tourism Investment Promotion Seminar Held in Singapore, Deepening Multi-Domain Cooperation to Empower Regional Growth // SCX Corporation Accelerates SC Group’s Recurring-Income Businesses // Adobe widens Saudi AI access with $4 billion programme // Putin holds talks with Pezeshkian in Bishkek // WisPaper Introduces TrueCite to Help Researchers Verify AI-Generated Academic References // Amicura X1 Max Smart Cat Litter Box:AliExpress France Official Warehouse, Litter Box at One Click // Venezuela defends sovereignty after Trump oil control claim // Schnabel urges programmable central bank money on-chain // US-Iran strikes revive confrontation across Hormuz and Jordan // India plans own orbital space outpost, second after China // Jungheinrich Marks 25 Years In Singapore, Leading APAC Strategic Hub And Electrification In The Market //