Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors fox tempest

Also known as: tracked as, Vice Spider, Vice Society, MuddyWater, Broomstick, a modular, enables the delivery, 560048

Description

Fox Tempest is a financially motivated criminal organization that runs a code‑signing‑as‑a‑service platform. By exploiting short‑lived Microsoft Artifact Signing certificates—typically valid for only 72 hours—the actor can sign malware binaries that appear legitimate, bypassing many Windows security checks that trust signed code. The MSaaS provisioned fully configured virtual machines and Azure subscriptions, allowing clients to deploy signed ransomware campaigns at scale. Clients pay between $5,000 and $9,000 through a public Google Form; in exchange they receive certificates, pre‑built VMs, and Telegram‑based support for troubleshooting and scaling. The service has been used by groups such as Vanilla Tempest and the Storm series to deliver malicious Microsoft Teams installer drops that host backdoors like Oyster and ultimately deploy ransomware like Rhysida. Following public awareness, Microsoft revoked thousands of compromised certificates in May 2026 and disrupted the signspace.cloud website and its Cloudzy‑hosted VM infrastructure. Fox Tempest’s operations showcase a sophisticated blend of social engineering, cloud abuse, and rapid pivoting that keeps attackers afloat even when key signing services are taken down. Their approach turns code‑signing into an open source marketplace for malware, creating a new supply chain model in the cybercriminal economy.

Goals & Targeting

Targeted Sectors

Healthcare
Education
Government
Financial services
Defense
Manufacturing
Critical infrastructure
Hospitality
Information technology
Media
Non profit
Construction
Telecommunications
Transportation
Think tank
Energy
Utilities
Retail

Targeted Countries / Regions

United States of America
British Indian Ocean Territory
China
France
India
US
CN
IN
GB
FR
CA
IL
IR
RU
KP
DE
ES
IT
AU

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 18 hours ago

Executive Summary

Fox Tempest operates a lucrative malware‑signing‑as‑a‑service (MSaaS) that issues short‑lived counterfeit Microsoft Artifact Signing certificates, enabling ransomware gangs to sign binaries and evade defenders. The service has driven large‑scale distribution of signed ransomware such as Rhysida and Vidar, targeting critical sectors worldwide. Recent takedowns in 2026 disrupted the provider’s website and cloud infrastructure but did not eliminate its impact.

Goals & Targeting

The actor aims to maximize financial gain by monetizing access to high‑trust certificates and cloud infrastructure. By supplying signed binaries that trick defenders, Fox Tempest enables widespread ransomware outbreaks that target high‑profile institutions—healthcare providers, educational establishments, government agencies, large enterprises, and critical utilities—to extract larger ransoms. Their focus on multi‑sector, multinational victims reflects a strategy of broad market penetration rather than narrow ideological objectives.

Enhanced Description

Key Capabilities

  • Generate short‑lived fraudulent Microsoft Artifact Signing certificates
  • Operate a malware‑signing‑as‑a‑service platform that issues compromised certificates and pre‑configured VMs
  • Create and manage Azure tenants/subscriptions to support malicious infrastructure
  • Provide digitally signed binaries for ransomware delivery
  • Offer a payment model via Google Form ($5k–$9k tiers)
  • Provision virtual machines and access to signing infrastructure on third‑party cloud services
  • Communicate with clients through a Telegram channel
  • Distribute signed malware via legitimate ad campaigns, malvertising, and SEO manipulation
  • Employ AI to generate campaign content
  • Quickly switch code‑signing providers after takedowns

MITRE ATT&CK Tactics

Resource Development
Defense Evasion
Execution
Persistence
Discovery
Command & Control
Impact
Initial Access

ATT&CK Techniques

T1059.001
T1036
T1189

Software / Tooling

Rhysida ransomware
Oyster malware
Lumma Stealer
Vidar ransomware
Vanilla Tempest (malware‑signing‑as‑a‑service)
Storm series (Storm-0501/2561/0249) ransomware
INC ransomware family
Qilin ransomware family
Akira ransomware family
signspace.cloud
Fox Tempest MSaaS
EV Certs for Sale (SamCodeSign)
Oyster Loader
Oyster backdoor
MuddyWater
Fragtor

Campaigns & Victims

Fox Tempest’s MSaaS has fueled a wave of signed‑binary ransomware campaigns across the globe since at least 2025. High‑profile operations—such as the distribution of signed Microsoft Teams installers that carried the Oyster backdoor and deployed Rhysida ransomware in hospitals and educational institutions—highlight a preference for fast, high‑impact attacks against systems where digital signatures are strongly trusted. The actor operates with an accelerated tempo: issuing thousands of certificates and hundreds of Azure tenants per month, scaling operations by leasing third‑party virtual machines when its primary signing sources are shut down. Victim selections span public sector, healthcare, education, finance, defense, and critical infrastructure, reflecting a broad threat profile aimed at maximizing financial return.

IOC Patterns

  • Fraudulent Microsoft Artifact Signing certificate
  • Short‑lived (72 hour) code‑signing certificate
  • Azure tenant/subscription misuse for malicious activity
  • Malicious signed binary masquerading as legitimate software
  • Cloud‑hosted virtual machine used to deliver signed malware
  • Signed .exe files masquerading as Microsoft Teams installers
  • Code‑signing certificates linked to Fox Tempest email accounts
  • Malicious MSTeamsSetup.exe downloads
  • Telegram-based client communication links
  • Google Form payment portal with tiered pricing
  • Signspace.cloud domain
  • Malvertising domains and SEO poisoning sites

Recommended Actions

  • Block or filter traffic to known compromised code‑signing services such as signspace.cloud.
  • Verify authenticity of all code signatures, particularly short‑lived certificates.
  • Implement continuous monitoring for new Azure tenant/subscription creation and suspicious usage patterns.
  • Detect and block malvertising and SEO poisoning channels that distribute signed malware.
  • Cooperate with cloud providers to identify and shut down malicious VMs used by Fox Tempest.
  • Revoke or blacklist fraudulent code‑signing certificates issued by the actor.
  • Enforce publisher allowlists, permitting only trusted binaries in controlled environments.
  • Employ behavior‑based detection for suspicious but signed executables.
  • Filter download traffic for Microsoft Teams installer URLs and cross‑validate signatures against official releases.
  • Educate users about phishing forms on public Google Forms and Telegram vendor communications.
  • Deploy certificate revocation lists (CRLs) and monitor certificate transparency logs for misuse.
  • Ensure layered security that does not rely solely on digital signature trust.
  • Maintain up‑to‑date malware detection rules that flag known families such as Rhysida, Vidar, Oyster, and Lumma Stealer.

ATT&CK Techniques

Execution
1 technique
Initial Access
1 technique
Stealth
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.microsoft.com — Cited by web research for: Broomstick
  2. www.cyfirma.com — Cited by web research for: 560048
  3. www.microsoft.com — Cited by web research for: Microsoft Teams
  4. blogs.microsoft.com — Cited by web research for: Global
  5. learn.microsoft.com — Cited by web research for: Tsunami
  6. www.malwarebytes.com — Cited by web research for: Guard
  7. www.cybersecuritydive.com — Cited by web research for: Manufacturing

Intel Summary

3

Techniques

62

Tools

0

Campaigns

12

IOCs

0

Observed Data

3

Tactics

Tags

Ransomware
Healthcare Targeting
Government Targeting

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
55%
Added
May 21, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.