Microsoft took decisive action to disrupt a sophisticated ransomware campaign orchestrated by the Vanilla Tempest threat group, also known as VICE SPIDER and Vice Society. The attackers exploited over 200 stolen or misused digital certificates to sign malicious Microsoft Teams installers, making their malware appear legitimate to both users and security software. This campaign, active in late September and early October, targeted users searching for Microsoft Teams updates by leveraging search engine optimization (SEO) poisoning and malvertising. Victims were lured to deceptive domains such as teams-download[.]buzz, teams-install[.]run, and teams-download[.]top, which closely mimicked official Microsoft Teams download sites. Unsuspecting users who downloaded and executed the fake MSTeamsSetup.exe files inadvertently installed a multi-stage payload. The initial loader deployed the Oyster backdoor, a versatile malware tool that Vanilla Tempest has used since June 2025. Once installed, Oyster provided the attackers with remote access, enabling them to steal files, execute arbitrary commands, and deploy additional malicious payloads. The campaign’s technical sophistication was heightened by the use of certificates from reputable providers like Trusted Signing, SSL.com, DigiCert, and GlobalSign, which were fraudulently used to sign the malware. Microsoft’s response involved revoking all compromised certificates, effectively neutralizing the attackers’ ability to distribute signed malware and disrupting ongoing infections. The group’s primary objective was financial gain through data exfiltration and ransomware deployment, with Rhysida ransomware being their recent tool of choice. Previous campaigns by Vanilla Tempest have also used ransomware strains such as BlackCat, Quantum Locker, and Zeppelin, but the current focus has been on Rhysida, particularly targeting sectors like healthcare, education, and manufacturing. The attackers’ use of malvertising and SEO poisoning demonstrates an evolving threat landscape where legitimate-looking software is weaponized to bypass traditional defenses. Microsoft’s intervention not only halted the immediate threat but also highlighted the importance of certificate management and vigilance against supply chain attacks. Security researchers emphasized the need for organizations to verify software sources and monitor for unusual certificate usage. The incident underscores the persistent risk posed by financially motivated ransomware groups and the necessity for coordinated industry responses to disrupt their operations. Organizations are advised to educate users about the dangers of downloading software from unofficial sources and to implement robust endpoint protection measures. The campaign’s exposure and Microsoft’s swift action serve as a warning to both defenders and attackers about the critical role of digital trust in modern cyber operations. This event also illustrates the increasing use of backdoors like Oyster in ransomware campaigns, enabling deeper and more persistent access to victim networks. The disruption of this campaign is a significant blow to Vanilla Tempest’s operations and a reminder of the ongoing arms race between threat actors and defenders.

TTPs, infrastructure, and targeting history in one profile.
9 events from the most recent confirmed update back to the earliest known activity.
Following publication of Microsoft's findings, DigiCert and GlobalSign said they had not yet been asked to revoke certificates mentioned in the reporting but would investigate and revoke them if misuse was confirmed. SSL.com had not responded at the time of reporting.
On October 16-17, 2025, Microsoft's disruption of the fake Teams installer campaign and certificate abuse became public through coordinated reporting. The disclosure detailed the infection chain, certificate revocations, and the actor's use of SEO poisoning and lookalike domains.
As part of the disruption, Microsoft updated Microsoft Defender Antivirus and Defender for Endpoint to detect and block the fake installers, Oyster backdoor, Rhysida ransomware, and related behaviors. It also published indicators of compromise and mitigation guidance for defenders.
In early October 2025, Microsoft disrupted the operation by revoking more than 200 code-signing certificates used to make malicious Teams installers and related malware appear legitimate. The revocations targeted certificates abused in Rhysida-linked intrusions attributed to Vanilla Tempest.
Microsoft said it uncovered the activity in late September 2025 after observing several months of fraudulently signed binaries used in attacks. The company attributed the operation to Vanilla Tempest, also tracked as VICE SPIDER/Vice Society.
In late September 2025, Vanilla Tempest pushed a campaign using SEO poisoning, malvertising, and lookalike Microsoft Teams download domains to distribute trojanized MSTeamsSetup.exe files. Executing the fake installer launched a loader that deployed Oyster and enabled eventual Rhysida ransomware attacks and data exfiltration.
Expel reported overlap between the Oyster campaign and Latrodectus malware through a shared Art en Code B.V. certificate used in mid-September 2025. This provided additional technical insight into certificate abuse tied to the campaign ecosystem.
By early September 2025, Vanilla Tempest had begun fraudulently code-signing Oyster backdoors, fake Microsoft Teams installers, and related tooling. Reports say the actor abused Microsoft Trusted Signing as well as certificates from commercial certificate authorities.
Microsoft assessed that the financially motivated threat actor Vanilla Tempest started integrating the Oyster backdoor into its intrusion activity as early as June 2025. Oyster was used as a signed loader/backdoor to enable follow-on access, data theft, and later ransomware deployment.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcehelpnetsecurity.com
Open sourcesecurityaffairs.com
Open sourcedarkreading.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.