Microsoft Disrupts Fox Tempest Malware-Signing Service

Microsoft unsealed a lawsuit and seized infrastructure to disrupt Fox Tempest, a malware-signing-as-a-service operation that helped ransomware gangs disguise malware as trusted software.

Microsoft Disrupts Fox Tempest Malware-Signing Service

Overview of a malware-signing-as-a-service operation

Microsoft has unsealed a legal case and seized infrastructure to disrupt Fox Tempest, a cybercrime service that since May 2025 helped attackers disguise malware as legitimate software. The action, filed in the U.S. District Court for the Southern District of New York, targets a malware-signing-as-a-service operation that the company says enabled ransomware and other attacks against thousands of machines worldwide.

How the service worked

Fox Tempest fraudulently accessed and abused code-signing tools, including Microsoft's Artifact Signing system, which is designed to verify that software is legitimate and untampered. Operators used fabricated identities and impersonated legitimate organizations to create hundreds of fraudulent Microsoft accounts and obtain real code-signing credentials in volume. Paying customers could then upload malicious files through an online portal to have them signed with Fox Tempest-controlled certificates, making the malware appear trustworthy to antivirus and other defenses. The malware was often disguised as trusted apps such as Microsoft Teams, AnyDesk, PuTTY and Webex.

The takedown

To disrupt the operation, Microsoft seized Fox Tempest's website, signspace[.]cloud, took hundreds of the virtual machines running the service offline, and blocked access to a site hosting the underlying code. Microsoft estimates the service generated more than 1,000 certificates and operated hundreds of Azure tenants and subscriptions. The company said the action is already having an impact, with cybercriminals complaining about difficulty accessing the service.

Ties to ransomware gangs

The lawsuit names the prominent ransomware group Vanilla Tempest as a co-conspirator, citing its use of the service to deploy malware such as Oyster, Lumma Stealer and Vidar, along with Rhysida ransomware. Microsoft linked Fox Tempest to additional affiliates and families including INC, Qilin and Akira. Rhysida has featured in high-profile attacks, including the theft and leak of internal documents from the British Library and disruption at Seattle-Tacoma International Airport. The seller charged thousands of dollars for the service, reflecting how valuable the capability had become.

A modular cybercrime economy

Microsoft framed the case as evidence that cybercrime is splintering into a modular ecosystem of specialized, interchangeable services, made more potent when paired with AI-driven tactics that scale and refine campaigns. The company is working with cybersecurity firm Resecurity, Europol's European Cybercrime Centre and the FBI, and warned that operators are already trying to shift to other code-signing services. The episode reflects mounting concern over AI-amplified security threats, governance debates such as the European Parliament's permanent AI and robotics committee, and the wider technology-decoupling pressures behind moves like the proposed U.S. ban on Chinese ground robots and scrutiny of connected industrial and drone connectivity systems.

Reporting based on coverage from Microsoft On the Issues and Axios.

Category: Cyber Security

Tags: Security Cybersecurity artificial intelligence

Related Articles