Back to feed
Dev.to
Dev.to
7/14/2026
Microsoft disrupts Fox Tempest malware-signing service linked to ransomware campaigns

Microsoft disrupts Fox Tempest malware-signing service linked to ransomware campaigns

Original: Microsoft Dismantles Fox Tempest: The $9K Malware-Signing Service Behind Ransomware's Trust Exploit

Short summary

Microsoft announced the takedown of Fox Tempest, a malware-signing-as-a-service operation that abused Microsoft's Artifact Signing system to create over 1,000 fraudulent code-signing certificates. The service charged $5,000–$9,000 per signing and supported ransomware families including Qilin, Akira, and INC. Security teams should audit code-signing trust policies, monitor for revoked certificates, and implement defense-in-depth rather than relying solely on signature validation.

  • Microsoft dismantled Fox Tempest, a service that created 1,000+ fraudulent code-signing certificates for ransomware gangs
  • The operation charged $5K–$9K per signing and was linked to Qilin, Akira, and INC ransomware families
  • Organizations should audit signing trust policies, hunt for affected certificates, and layer endpoint defenses beyond signature validation

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more