BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Microsoft Disrupts Major Ransomware-Signing Operation

Microsoft dismantles Fox Tempest malware-signing service abusing its Artifact Signing system.

  • Microsoft disrupted Fox Tempest, a malware-signing-as-a-service that weaponized its Artifact Signing system to legitimize ransomware and other malware.
  • The service sold for between $5,000 and $9,000, enabling attacks on thousands of machines globally in sectors like healthcare and government.
  • The operation facilitated the distribution of Rhysida, Oyster, Lumma Stealer, and Vidar malware, often disguised as legitimate software like AnyDesk or Microsoft Teams.
  • Microsoft seized the operation’s website, signspace[.]cloud, and took hundreds of virtual machines offline in an effort codenamed OpFauxSign.

In a significant crackdown on a critical cybercrime enabler, Microsoft announced it has dismantled a sophisticated malware-signing service that abused its own security tools to legitimize ransomware attacks globally. The tech giant, working through its Digital Crimes Unit, attributed the operation to a threat actor it tracks as Fox Tempest, which had been active since May 2025.

- Advertisement -

Steven Masada, assistant general counsel at Microsoft, said the disruption involved seizing the service’s website and taking hundreds of virtual machines offline. Consequently, the scheme, which Microsoft codenamed OpFauxSign, was a key distributor for ransomware groups like Vanilla Tempest. The service fraudulently obtained short-lived code-signing certificates through Microsoft’s Artifact Signing system, making malicious files appear trusted.

Paying customers, including affiliates linked to INC, Qilin, BlackByte, and Akira ransomware, used the service to sign malware for between $5,000 and $9,000. Microsoft explained that the threat actor likely used stolen identities to pass validation checks. This allowed malware like Rhysida ransomware and the Oyster loader to be disguised as legitimate software.

Meanwhile, the operation evolved in early 2026 to provide pre-configured virtual machines for greater efficiency and security. However, Microsoft enacted countermeasures, such as revoking illicit certificates and disabling fraudulent accounts. “When attackers can make malicious software look legitimate, it undermines how people and systems decide what’s safe,” the company stated, emphasizing the importance of such disruptions.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Institutional Investors Boost MSTR Positions Amid Bitcoin Rally

Thirteen of Strategy's 15 largest institutional shareholders increased their stakes in the company during...

GitHub breach via poisoned VS Code extension

A breach of GitHub's internal repositories originated from an employee downloading a malicious extension...

10% of Bitcoin Supply Vulnerable to Quantum Attack

Nearly 10% of Bitcoin's total supply, or roughly 1.92 million BTC, is "structurally unsafe"...

Analysts Bullish on Micron, Targets Up to $1,100 as AI Demand Soars

Micron shares are a market focal point, with 92% of analysts maintaining a Buy...

Nexo Reups Golf Sponsorship, $3M Prize At Trump Links

Nexo renewed its title sponsorship of the DP World Tour's Nexo Championship golf tournament.The...

Must Read

Symbiosis Crypto Bridge: Your Guide to Moving Assets Between Blockchains

What is a Cross-Chain Crypto Bridge?Why Choose Symbiosis for Your Cross-Chain Needs?Support for 50+ BlockchainsAutomatic Routing for the Best RatesNo Need for RegistrationDirect Wallet...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading