Microsoft says it disrupts a malware-signing-as-a-service operation that it links to a threat actor it calls “Fox Tempest.” The company reports that the actors used Microsoft’s Artifact Signing system to sign and deliver malicious code that is disguised as legitimate software. Microsoft states the activity supported ransomware and other cyberattacks and resulted in compromises across thousands of machines and networks worldwide.
According to Microsoft, the service functioned as a distribution mechanism for criminals seeking trusted-looking malware signatures, enabling wider deployment of malicious software. SecurityWeek similarly describes “Fox Tempest” as providing a service used by cybercriminals to spread ransomware and other malware under the appearance of legitimate software.
Both outlets frame the disruption as an intervention against the infrastructure used for malware delivery and signing, rather than a single incident. Microsoft’s attribution to “Fox Tempest” identifies the actor behind the operation, and it positions the case as part of broader efforts to reduce the effectiveness of signed malware in real-world attacks.