Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Exposing Fox Tempest: A malware-signing service operation

signspace.cloud

TLP:CLEAR
Active

Domain

Description

Fox Tempest is a financially motivated threat actor operating a malware-signing-as-a-service (MSaaS) business used by cybercriminals to distribute malicious code, including ransomware. The actor abuses Microsoft Artifact Signing to generate fraudulent code-signing certificates, allowing malware to evade security controls. Fox Tempest created over a thousand certificates and established hundreds of Azure tenants to support operations. Microsoft revoked over one thousand certificates and disrupted the service in May 2026 through the Digital Crimes Unit. The operation enabled ransomware deployment including Rhysida by threat actors like Vanilla Tempest, and distributed malware families including Oyster, Lumma Stealer, and Vidar. The MSaaS was available through signspace[.]cloud, charging between $5000-$9000 USD. Attacks impacted healthcare, education, government, and financial services sectors globally.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Exposing Fox Tempest: A malware-signing service operation
Pattern Type
STIX
Confidence
75%
Valid From
May 21, 2026 03:05
Total Sightings
0
Added
May 21, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of signspace.cloud

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.