Forging Marauder, also known as Fox Tempest, is a malware-signing-as-a-service provider associated with supplying fraudulently signed Microsoft Trusted Signing certificates to other threat operators since at least June 2025. Its role is to enable downstream intrusion sets to make malicious payloads appear more trustworthy and thereby improve delivery success and defense evasion. High-confidence reporting links its certificate supply to operators in the Lorem Ipsum and Rapid Brigantine ecosystem, which used signed fake software installers before shifting to alternative delivery methods after disruption activity in May 2026. Forging Marauder is therefore best characterized as an enabling criminal service within the cybercrime ecosystem rather than a standalone intrusion cluster defined by its own victimology. The directly supported capability is defense evasion through provision of fraudulent code-signing material. Its dominant motivation is financial.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.