Dev.to
7/14/2026

Microsoft disrupts Fox Tempest malware-signing service linked to ransomware campaigns
Original: Microsoft Dismantles Fox Tempest: The $9K Malware-Signing Service Behind Ransomware's Trust Exploit
Short summary
Microsoft announced the takedown of Fox Tempest, a malware-signing-as-a-service operation that abused Microsoft's Artifact Signing system to create over 1,000 fraudulent code-signing certificates. The service charged $5,000–$9,000 per signing and supported ransomware families including Qilin, Akira, and INC. Security teams should audit code-signing trust policies, monitor for revoked certificates, and implement defense-in-depth rather than relying solely on signature validation.
- •Microsoft dismantled Fox Tempest, a service that created 1,000+ fraudulent code-signing certificates for ransomware gangs
- •The operation charged $5K–$9K per signing and was linked to Qilin, Akira, and INC ransomware families
- •Organizations should audit signing trust policies, hunt for affected certificates, and layer endpoint defenses beyond signature validation
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



