Microsoft said it disrupted Fox Tempest, a malware-signing-as-a-service operation that helped cybercriminals make malicious software appear legitimate by abusing code-signing tools including Microsoft Artifact Signing. The company unsealed a case in the U.S. District Court for the Southern District of New York, alleging the group used fabricated identities and impersonated organizations to create hundreds of fraudulent Microsoft accounts and obtain code-signing credentials at scale, generating millions in proceeds. Microsoft linked the service to infections on thousands of machines and to malware and ransomware including Oyster, Lumma Stealer, Vidar, Rhysida, and affiliates tied to INC, Qilin, and Akira.
As part of the disruption, Microsoft seized the signspace[.]cloud website, took hundreds of virtual machines offline, and blocked access to another site hosting the underlying code. The lawsuit also names Vanilla Tempest as a co-conspirator, and Microsoft said the service had supported attacks across healthcare, education, government, and financial services in countries including the United States, France, India, and China. According to Microsoft, Fox Tempest adapted after earlier defensive actions by shifting to third-party-hosted virtual machines and trying to move customers to another signing service, underscoring how commercialized code-signing services are being used to improve ransomware delivery and evade detection.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
Microsoft said it is continuing disruption efforts in coordination with Resecurity, Europol EC3, and the FBI, while working to strengthen the broader code-signing ecosystem. The announcement framed Fox Tempest as part of a growing modular cybercrime market for illicit code-signing services.
On 2026-05-19, Microsoft said it revoked more than 1,000 code-signing certificates associated with the Fox Tempest malware-signing service. The revocations were part of the broader disruption that also included seizing the group's website and taking infrastructure offline.
On May 19, 2026, Microsoft announced it had unsealed a case in the U.S. District Court for the Southern District of New York against Fox Tempest and named Vanilla Tempest as a co-conspirator. As part of the disruption, Microsoft seized the signspace[.]cloud website, took hundreds of virtual machines offline, and blocked access to a site hosting the underlying code.
Microsoft filed a civil action against Fox Tempest in the U.S. District Court for the Southern District of New York on May 5, 2026, and obtained a court order on May 8. The legal action enabled subsequent sinkholing, account takedowns, VM disruptions, and repository suspension tied to the operation.
Between February and March 2026, investigators conducted undercover purchases from the Fox Tempest malware-signing service to observe how it operated, gather operational details, and identify cryptocurrency wallets linked to the defendants. The activity helped document the service ahead of Microsoft's legal and disruption actions.
Microsoft said that in February 2026, Fox Tempest adapted to defensive actions by moving to third-party-hosted virtual machines and attempting to migrate customers to another code-signing service. The change indicated the group was responding to pressure on its existing infrastructure and tooling.
After launching, the service was used to sign malware tied to campaigns involving Oyster, Lumma Stealer, Vidar, Rhysida, and other ransomware affiliates and families including INC, Qilin, and Akira. Microsoft said these downstream attacks infected thousands of machines across sectors including healthcare, education, government, and financial services in countries including the United States, France, India, and China.
Microsoft said Fox Tempest began operating in May 2025, offering a service that helped cybercriminals make malware appear legitimate by abusing code-signing tools such as Microsoft Artifact Signing. The operation allegedly used fabricated identities and impersonated organizations to create fraudulent Microsoft accounts and obtain signing credentials at scale.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
20 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcesecurityaffairs.com
Open sourcesecurityonline.info
Open sourcexakep.ru
Open sourcetheregister.com
Open sourceblogs.microsoft.com
Open sourceblogs.microsoft.com
Open sourceaka.ms
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.