Fox Tempest is a financially motivated cybercrime enabler that operates a malware-signing-as-a-service (MSaaS) offering for other threat actors. Active since at least May 2025, the group abused Microsoft Artifact Signing, formerly Trusted Signing, to obtain large volumes of short-lived fraudulent code-signing certificates and use them to sign malicious binaries so they appeared legitimate to users and security controls. The operation functioned as an upstream service provider in the malware and ransomware ecosystem rather than primarily conducting victim intrusions directly. Fox Tempest’s service allowed customers to submit malware for signing and receive binaries disguised as trusted software, materially improving delivery success and defense evasion. Reporting links the service to malware and ransomware activity involving Oyster, Lumma Stealer, Vidar, Rhysida, Akira, INC, Qilin, and BlackByte, and to customers or associated actors including Vanilla Tempest, Storm-0501, Storm-2561, and Storm-0249. In observed chains, signed trojanized software installers were distributed through malvertising, SEO poisoning, fake download pages, and other social-engineering-driven delivery methods, after which downstream actors deployed loaders, stealers, backdoors, and ransomware. The group is assessed to have operated at scale, creating more than 1,000 fraudulent certificates and hundreds of cloud tenants and subscriptions to support the service. Fox Tempest also expanded to provide preconfigured virtual-machine environments to streamline customer access to signing workflows. The operation relied on fabricated or stolen identities, including evidence pointing to identities from the United States and Canada, to satisfy verification requirements for certificate issuance. Customers reportedly paid thousands of dollars per signing tier, indicating a mature commercialized criminal service model. Fox Tempest is also referred to as Forging Marauder. Its core capability is weaponized code-signing abuse to help other criminals evade trust-based controls, reduce early detection, and increase the credibility of malicious software. The actor’s dominant motivation is financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ran a malware-signing-as-a-service operation using fraudulently signed Microsoft Trusted Signing certificates to facilitate malware delivery with reduced detection.
Malware-signing-as-a-service provider whose infrastructure supplied fraudulently obtained Microsoft Trusted Signing certificates used to sign malicious installers.
Operates a malware-signing service that provides fraudulent code-signing for malware used by multiple criminal actors.
Financially motivated threat actor operating a malware-signing-as-a-service offering used by other threat actors to sign malware and improve trust and evasion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.