Also known as: tracked as, Vice Spider, Vice Society, MuddyWater, Broomstick, a modular, enables the delivery, 560048
Fox Tempest is a financially motivated criminal organization that runs a code‑signing‑as‑a‑service platform. By exploiting short‑lived Microsoft Artifact Signing certificates—typically valid for only 72 hours—the actor can sign malware binaries that appear legitimate, bypassing many Windows security checks that trust signed code. The MSaaS provisioned fully configured virtual machines and Azure subscriptions, allowing clients to deploy signed ransomware campaigns at scale. Clients pay between $5,000 and $9,000 through a public Google Form; in exchange they receive certificates, pre‑built VMs, and Telegram‑based support for troubleshooting and scaling. The service has been used by groups such as Vanilla Tempest and the Storm series to deliver malicious Microsoft Teams installer drops that host backdoors like Oyster and ultimately deploy ransomware like Rhysida. Following public awareness, Microsoft revoked thousands of compromised certificates in May 2026 and disrupted the signspace.cloud website and its Cloudzy‑hosted VM infrastructure. Fox Tempest’s operations showcase a sophisticated blend of social engineering, cloud abuse, and rapid pivoting that keeps attackers afloat even when key signing services are taken down. Their approach turns code‑signing into an open source marketplace for malware, creating a new supply chain model in the cybercriminal economy.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Fox Tempest operates a lucrative malware‑signing‑as‑a‑service (MSaaS) that issues short‑lived counterfeit Microsoft Artifact Signing certificates, enabling ransomware gangs to sign binaries and evade defenders. The service has driven large‑scale distribution of signed ransomware such as Rhysida and Vidar, targeting critical sectors worldwide. Recent takedowns in 2026 disrupted the provider’s website and cloud infrastructure but did not eliminate its impact.
Goals & Targeting
The actor aims to maximize financial gain by monetizing access to high‑trust certificates and cloud infrastructure. By supplying signed binaries that trick defenders, Fox Tempest enables widespread ransomware outbreaks that target high‑profile institutions—healthcare providers, educational establishments, government agencies, large enterprises, and critical utilities—to extract larger ransoms. Their focus on multi‑sector, multinational victims reflects a strategy of broad market penetration rather than narrow ideological objectives.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Fox Tempest’s MSaaS has fueled a wave of signed‑binary ransomware campaigns across the globe since at least 2025. High‑profile operations—such as the distribution of signed Microsoft Teams installers that carried the Oyster backdoor and deployed Rhysida ransomware in hospitals and educational institutions—highlight a preference for fast, high‑impact attacks against systems where digital signatures are strongly trusted. The actor operates with an accelerated tempo: issuing thousands of certificates and hundreds of Azure tenants per month, scaling operations by leasing third‑party virtual machines when its primary signing sources are shut down. Victim selections span public sector, healthcare, education, finance, defense, and critical infrastructure, reflecting a broad threat profile aimed at maximizing financial return.
IOC Patterns
Recommended Actions
No campaigns linked yet.
No observed data linked yet.
3
Techniques
62
Tools
0
Campaigns
12
IOCs
0
Observed Data
3
Tactics