BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Microsoft Disrupts Major Ransomware-Signing Operation

Microsoft dismantles Fox Tempest malware-signing service abusing its Artifact Signing system.

  • Microsoft disrupted Fox Tempest, a malware-signing-as-a-service that weaponized its Artifact Signing system to legitimize ransomware and other malware.
  • The service sold for between $5,000 and $9,000, enabling attacks on thousands of machines globally in sectors like healthcare and government.
  • The operation facilitated the distribution of Rhysida, Oyster, Lumma Stealer, and Vidar malware, often disguised as legitimate software like AnyDesk or Microsoft Teams.
  • Microsoft seized the operation’s website, signspace[.]cloud, and took hundreds of virtual machines offline in an effort codenamed OpFauxSign.

In a significant crackdown on a critical cybercrime enabler, Microsoft announced it has dismantled a sophisticated malware-signing service that abused its own security tools to legitimize ransomware attacks globally. The tech giant, working through its Digital Crimes Unit, attributed the operation to a threat actor it tracks as Fox Tempest, which had been active since May 2025.

- Advertisement -

Steven Masada, assistant general counsel at Microsoft, said the disruption involved seizing the service’s website and taking hundreds of virtual machines offline. Consequently, the scheme, which Microsoft codenamed OpFauxSign, was a key distributor for ransomware groups like Vanilla Tempest. The service fraudulently obtained short-lived code-signing certificates through Microsoft’s Artifact Signing system, making malicious files appear trusted.

Paying customers, including affiliates linked to INC, Qilin, BlackByte, and Akira ransomware, used the service to sign malware for between $5,000 and $9,000. Microsoft explained that the threat actor likely used stolen identities to pass validation checks. This allowed malware like Rhysida ransomware and the Oyster loader to be disguised as legitimate software.

Meanwhile, the operation evolved in early 2026 to provide pre-configured virtual machines for greater efficiency and security. However, Microsoft enacted countermeasures, such as revoking illicit certificates and disabling fraudulent accounts. “When attackers can make malicious software look legitimate, it undermines how people and systems decide what’s safe,” the company stated, emphasizing the importance of such disruptions.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Cronos halts network after $75M Tectonic exploit

Cronos halted its blockchain after an exploit targeting Tectonic involved an estimated $75 millioncrypto.com...

PayPal Down 13% as Advent, Stripe Drop Bid; Retail Bullish

Paypal stock plunged nearly 13% last week after reports that Advent and Stripe abandoned...

Polygon Labs quietly fixes critical security bugs with hard forks

Polygon Labs disclosed it patched a batch of security vulnerabilities through two hard forks...

Saylor Signals ‘We’re Back’ as Strategy Set to Resume Bitcoin Buys

Strategy co-founder Michael Saylor posted a cryptic message on X, signaling the company's likely...

India pitches CBDC link for BRICS trade at upcoming summit

India will propose a central bank digital currency (CBDC) linkage at the BRICS summit...

Must Read

14 Ways On How to Make Money with Cryptocurrency

Many people want to make money with cryptocurrency because they have heard the success stories of people who became millionaires from zero.If you...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading