Microsoft disrupts Fox Tempest, a malware signing service

Microsoft has taken legal and technical action against Fox Tempest, a malware-signing-as-a-service operation that allegedly helped criminals make malicious software appear legitimate. The service abused code-signing tools, including Microsoft Artifact Signing, using fabricated identities and fraudulent accounts to obtain certificates at scale.

The disruption included seizing the signspace[.]cloud website, taking hundreds of virtual machines offline, blocking access to related code, revoking fraudulent certificates and strengthening account verification. Microsoft links the service to ransomware actors including Vanilla Tempest, and to malware families such as Oyster, Lumma Stealer and Vidar, as well as ransomware including Rhysida, INC, Qilin and Akira. The case illustrates the growing specialisation of cybercrime infrastructure, where attackers buy services that remove operational barriers and improve success rates.

What this means for your business

A signature is no longer proof that software can be trusted. Many organisations have rules that let signed code through without further checks, and that rule was precisely Fox Tempest's business model. The consequence is that detection must rest on what software does, not only on who signed it.

Berigo recommends

  • Review endpoint protection rules that exempt signed code, and narrow them to named publishers rather than signed code in general.
  • Deploy behaviour-based detection that triggers even when a file carries a valid signature.
  • Review who in the organisation can install software themselves, and reduce that number.
  • Include code signing and publisher verification in your requirements for software suppliers.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch