Summary
Microsoft’s Digital Crimes Unit announced today the seizure and disruption of infrastructure belonging to Fox Tempest, a financially-motivated threat group that operated a sophisticated malware-signing-as-a-service platform. The operation, backed by a court order, dismantled a service that had created and sold over 1,000 fraudulent code-signing certificates to ransomware operators and other cybercriminals.
Fox Tempest, tracked by Microsoft since September 2025, abused Microsoft’s own Artifact Signing system by fabricating identities and impersonating legitimate organizations. Their customers — including the Rhysida, Vanilla Tempest, Storm-0501, Storm-2561, and Storm-0249 ransomware groups — paid up to $9,500 per signing to make their malware appear as trusted, legitimate software. The service featured an authenticated portal with a drag-and-drop interface for getting malicious code signed.
The fraudulent certificates were primarily used in malvertising and SEO poisoning campaigns, pushing infostealers and ransomware to the top of search results where victims would unwittingly download and run them. The operation was directly linked to the deployment of dozens of malware families, including Oyster and Lumma Stealer.
Source
CyberScoop | Infosecurity Magazine
Commentary
This takedown highlights an often-overlooked layer of the cybercrime supply chain: the infrastructure that makes attacks look legitimate. Fox Tempest wasn’t writing malware — they were laundering it through the trust systems that organizations rely on to distinguish safe software from dangerous software. It’s the digital equivalent of a counterfeiting ring for passports, and it made every downstream attack harder to detect.
The $9,500 price point is also telling. At that rate, code-signing fraud is accessible to mid-tier ransomware affiliates, not just nation-state actors. As Microsoft’s DCU put it: attackers are no longer just tricking users to click links — they’re exploiting the very systems we use to decide what is and isn’t safe. Expect more focus on supply-chain trust mechanisms in the months ahead.
