BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Microsoft Disrupts Major Ransomware-Signing Operation

Microsoft dismantles Fox Tempest malware-signing service abusing its Artifact Signing system.

  • Microsoft disrupted Fox Tempest, a malware-signing-as-a-service that weaponized its Artifact Signing system to legitimize ransomware and other malware.
  • The service sold for between $5,000 and $9,000, enabling attacks on thousands of machines globally in sectors like healthcare and government.
  • The operation facilitated the distribution of Rhysida, Oyster, Lumma Stealer, and Vidar malware, often disguised as legitimate software like AnyDesk or Microsoft Teams.
  • Microsoft seized the operation’s website, signspace[.]cloud, and took hundreds of virtual machines offline in an effort codenamed OpFauxSign.

In a significant crackdown on a critical cybercrime enabler, Microsoft announced it has dismantled a sophisticated malware-signing service that abused its own security tools to legitimize ransomware attacks globally. The tech giant, working through its Digital Crimes Unit, attributed the operation to a threat actor it tracks as Fox Tempest, which had been active since May 2025.

- Advertisement -

Steven Masada, assistant general counsel at Microsoft, said the disruption involved seizing the service’s website and taking hundreds of virtual machines offline. Consequently, the scheme, which Microsoft codenamed OpFauxSign, was a key distributor for ransomware groups like Vanilla Tempest. The service fraudulently obtained short-lived code-signing certificates through Microsoft’s Artifact Signing system, making malicious files appear trusted.

Paying customers, including affiliates linked to INC, Qilin, BlackByte, and Akira ransomware, used the service to sign malware for between $5,000 and $9,000. Microsoft explained that the threat actor likely used stolen identities to pass validation checks. This allowed malware like Rhysida ransomware and the Oyster loader to be disguised as legitimate software.

Meanwhile, the operation evolved in early 2026 to provide pre-configured virtual machines for greater efficiency and security. However, Microsoft enacted countermeasures, such as revoking illicit certificates and disabling fraudulent accounts. “When attackers can make malicious software look legitimate, it undermines how people and systems decide what’s safe,” the company stated, emphasizing the importance of such disruptions.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

GreatXML Bypass Exposes Windows BitLocker Security

A new Windows BitLocker encryption bypass tool named GreatXML has been released by security...

Ex-Engineer Sues xAI, SpaceX Over Grok Safety Warnings

Former xAI engineer Devin Kim has sued xAI and SpaceX, alleging wrongful termination after...

OpenAI Acquires Ona To Bolster Autonomous AI Agents

OpenAI will acquire cloud platform startup Ona to bolster its development of autonomous AI...

Bithumb CEO booked for suspected job-for-favors bribery

Bithumb CEO Lee Jae-won was booked by South Korean police on June 11, 2026,...

MassPay, Coinbase Partner on Stablecoin Cross-Border Payouts

MassPay and Coinbase partnered to offer stablecoin-based cross-border payouts across 180 countries.The new system...

Must Read

6 Best VPN Providers That Accept Monero

Privacy and anonymity are probably the most important things that we should all consider in today's internet era. Although there are a lot of...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading