Fox Tempest Malware-Signing-as-a-Service (MSaaS) — Microsoft DCU Disrupts signspace[.]cloud Operation Enabling Rhysida, INC, Qilin, Akira & Vanilla Tempest

Fox Tempest Malware-Signing-as-a-Service (MSaaS) (TL-2026-0533), also tracked as signspace.cloud operation, is a high-severity malware campaign, first published 2026-05-19. It is attributed to Fox Tempest (Russia) with medium confidence, affects Microsoft Microsoft Artifact Signing (Azure Trusted Signing), maps to 32 MITRE ATT&CK techniques (T1005, T1021.002, T1036.001), and is covered by 9 detection rules and 22 indicators of compromise.

Key facts for TL-2026-0533

Threat ID
TL-2026-0533
Also known as
signspace.cloud operation, MSaaS — Microsoft Artifact Signing abuse, SamCodeSign service
Severity
HIGH
Status
MONITORING
Category
MALWARE
First published
2026-05-19
Last reviewed
2026-05-19
Attribution
Fox Tempest
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
healthcare, education, government, financial-services
Target regions
United States, France, India, China
Detection rules
9
Indicators of compromise
22

Malware and tooling in Fox Tempest Malware-Signing-as-a-Service (MSaaS)

Malware and tooling: AgendaCrypt, Akira, BlackByte, Broomstick, Lumma Stealer - S1213, Vidar, inc ransom, rhysida, Azure tenants/subscriptions registered with stolen US and Canada identities

Fox Tempest is a financially motivated, Russian-speaking criminal enterprise that operated signspace[.]cloud, a Malware-Signing-as-a-Service (MSaaS) platform that abused Microsoft Artifact Signing (formerly Azure Trusted Signing) to mint short-lived (72-hour) fraudulent code-signing certificates for paying ransomware and infostealer affiliates. Microsoft's Digital Crimes Unit (DCU) disrupted the operation on 2026-05-19 after eight months of tracking, revoking 1,000+ certificates across hundreds of Azure tenants and subscriptions registered with stolen US/Canadian identities. Customers — including Vanilla Tempest, Storm-0501, Storm-2561, and Storm-0249 — used Fox Tempest-signed binaries to deliver Rhysida, INC, Qilin, Akira, and BlackByte ransomware as well as Oyster (Broomstick), Lumma Stealer, and Vidar via SEO poisoning, malvertising, and trojanized installers masquerading as AnyDesk, Microsoft Teams, PuTTY, and Webex.

How Fox Tempest Malware-Signing-as-a-Service (MSaaS) works

Fox Tempest is the Microsoft Threat Intelligence cryptonym for a financially motivated, likely Russian-speaking cybercriminal group that built and operated a turnkey Malware-Signing-as-a-Service (MSaaS) platform hosted at signspace[.]cloud. The service was first offered in May 2025, picked up its first known affiliate customer (Vanilla Tempest) in June 2025, came under sustained Microsoft Threat Intelligence tracking in September 2025, and was disrupted by Microsoft DCU on 19 May 2026 — by which time over 1,000 fraudulent code-signing certificates had been issued through it.

The abuse target was Microsoft Artifact Signing (formerly Azure Trusted Signing), a cloud-managed signing service designed to give legitimate ISVs a Microsoft-rooted certificate chain (issuer 'Microsoft ID Verified CS EOC CA 01') with very short — 72 hour — leaf validity. Fox Tempest weaponized that design property: short-lived certs leave no useful long-lived revocation list to seed reputation systems on, while the chain to Microsoft's root made the signed binary appear high-trust to SmartScreen, EDR reputation lookups, application allowlisting (Software Restriction Policies, AppLocker, WDAC publisher rules), and analyst triage. To pass Trusted Signing identity validation, the operators acquired (very likely purchased on criminal markets) stolen identity documents from US- and Canada-based individuals and small businesses, used those identities to stand up hundreds of Azure tenants and subscriptions, and onboarded each to Trusted Signing as a separate 'publisher.' Each tenant became a disposable signing oracle: a customer's PE file went in, came back signed by a Microsoft-rooted leaf cert tied to a synthetic 'publisher' identity, and was burned within 72 hours.

The customer-facing portal at signspace[.]cloud was a full SaaS offering: an admin panel managing tooling and customer accounts, a customer upload interface for unsigned malicious binaries, a structured backend database tracking users and submissions, and configuration files linked to a GitHub repository named 'code-signing-service.' From May 2025 through February 2026 customers uploaded binaries directly through the web portal. From February 2026 onward, Fox Tempest matured the offering: customers were provisioned a pre-configured US-based Cloudzy VPS that handled upload, signing, and return of the binary, reducing operational friction and obscuring the link between portal and signing tenant. Pricing was tiered between USD 5,000 and USD 9,000 via a Google Form, with higher-paying customers receiving signing-queue priority. Sales and support were brokered on Telegram under the handle @arbadakarba2000 (channel name 'EV Certs for Sale by SamCodeSign'). Operator-facing documentation was bilingual English/Russian — the primary linguistic attribution signal — and cryptocurrency tracing tied wallets to known ransomware affiliate clusters, supporting the assessment that Fox Tempest is a well-resourced criminal enterprise with dedicated roles for infrastructure, customer ops, and finance.

Downstream impact spanned the top tier of the criminal ransomware ecosystem. Vanilla Tempest (the Rhysida operator) used Fox Tempest signatures from June 2025 onward to sign trojanized Microsoft Teams installers delivered via purchased Google/Bing advertisements; the loader stage was Oyster/Broomstick, terminating in Rhysida deployment. Storm-2561 used Fox Tempest-signed fake VPN clients distributed via SEO poisoning. Storm-0501 and Storm-0249 used Fox Tempest signatures across active intrusions ending in INC, Qilin, Akira, and BlackByte ransomware. Infostealer affiliates used the signing service to push Lumma Stealer and Vidar past SmartScreen and reputation gates. Microsoft estimates extortion proceeds attributable to Fox Tempest-signed campaigns 'in the millions' of US dollars, with confirmed victims across healthcare, education, government, and financial services in the United States, France, India, and China.

The full exploit chain, end to end: (1) An affiliate procures a binary (loader, dropper, or stage-two implant) and uploads it through signspace[.]cloud or the Cloudzy VM. (2) Fox Tempest's backend selects an unburned Azure tenant — registered with a stolen US/Canada identity and onboarded to Microsoft Artifact Signing — and submits a signing request, which Microsoft Artifact Signing fulfills against that tenant's policy. (3) A short-lived (72h) leaf certificate chained to 'Microsoft ID Verified CS EOC CA 01' is bound to the binary, which is returned to the customer. (4) The customer distributes the signed binary via SEO poisoning (typosquatted or SEO-stuffed download pages ranking for 'anydesk download,' 'putty,' 'webex installer,' 'microsoft teams,' free VPN clients) and/or malvertising (purchased Google Ads and Bing Ads redirecting through cloaked affiliate networks to the fake download). (5) Victim downloads, sees a Microsoft-rooted publisher signature, and runs the installer. (6) Loader (Oyster/Broomstick, or a stealer dropper) executes; Defender SmartScreen and many EDR reputation engines treat the binary as trusted on signature. (7) For ransomware tracks, the loader fetches second-stage tooling (Cobalt Strike, Sliver, or operator-specific implants), performs discovery and credential access, moves laterally, exfiltrates data, and detonates Rhysida/INC/Qilin/Akira/BlackByte. For stealer tracks, Lumma or Vidar harvests credentials, cookies, MFA tokens, and crypto wallets and exfiltrates to operator C2.

The Microsoft DCU disruption on 2026-05-19 included: revocation of 1,000+ certificates issued through Fox Tempest tenants, takedown of signspace[.]cloud, coordination with Cloudzy to identify and de-provision Fox Tempest-controlled VMs, and Defender signature pushes covering Oyster, Lumma, Vidar, Malcert, Rhysida, INC, Qilin, and BlackByte family detections plus a Vanilla Tempest activity-group profile. Defenders should treat any binary with a 'Microsoft ID Verified CS EOC CA 01' leaf signature between May 2025 and May 2026 as potentially abused unless explicitly attributable to a known legitimate ISV. Hunt for the published SignerSha-1 thumbprints, retro-hunt on the SHA-256, and audit signed-binary execution from user-writable paths and recent download locations. Long-term defenders should enforce publisher allowlisting (WDAC) against an explicit list of trusted publishers rather than relying on Microsoft chain trust alone, since Microsoft Artifact Signing assigns chain trust to any onboarded tenant.

MITRE ATT&CK techniques used in TL-2026-0533

Collection

T1005 Data from Local System

Lateral Movement

T1021.002 Remote Services: SMB/Windows Admin Shares

Defense Evasion

T1036.001 Invalid Code Signature; T1036.005 Match Legitimate Resource Name or Location; T1070.004 Indicator Removal: File Deletion

Exfiltration

T1041 Exfiltration Over C2 Channel

Discovery

T1057 Process Discovery; T1082 System Information Discovery

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1204.002 User Execution: Malicious File

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1105 Ingress Tool Transfer

Initial Access

T1189 Drive-by Compromise; T1566.002 Phishing: Spearphishing Link

Impact

T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery

Credential Access

T1539 Steal Web Session Cookie; T1555.003 Credentials from Password Stores: Credentials from Web Browsers

Persistence

T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

defense-impairment

T1553.002 Subvert Trust Controls: Code Signing; T1553.003 Subvert Trust Controls: SIP and Trust Provider Hijacking; T1685 Disable or Modify Tools

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1583.003 Acquire Infrastructure: Virtual Private Server; T1583.006 Acquire Infrastructure: Web Services; T1585.003 Establish Accounts: Cloud Accounts; T1586.002 Email Accounts; T1588.003 Obtain Capabilities: Code Signing Certificates; T1588.004 Obtain Capabilities: Digital Certificates; T1608.001 Stage Capabilities: Upload Malware; T1608.004 Stage Capabilities: Drive-by Target; T1608.006 Stage Capabilities: SEO Poisoning

Affected products and versions in Fox Tempest Malware-Signing-as-a-Service (MSaaS)

  • Microsoft — Microsoft Artifact Signing (Azure Trusted Signing)
    Vulnerable versions: service-wide identity-validation bypass via stolen US/Canada identities, 2025-05 through 2026-05
    Fixed in: 1,000+ certificates revoked 2026-05-19; identity validation hardening per Microsoft DCU disruption
  • Microsoft — Windows code-signing trust chain (Microsoft ID Verified CS EOC CA 01)
    Vulnerable versions: any Windows host treating Microsoft-rooted Authenticode signatures as high-reputation 2025-05 through 2026-05
    Fixed in: Defender signatures updated 2026-05-19; SmartScreen/MAPS reputation updated; revoked thumbprints distributed via Windows CTL
  • AnyDesk — AnyDesk Remote Desktop (impersonated)
    Vulnerable versions: legitimate brand impersonated by Fox Tempest-signed trojanized installers
  • Microsoft — Microsoft Teams (impersonated)
    Vulnerable versions: legitimate brand impersonated by Vanilla Tempest using Fox Tempest signatures, June 2025-May 2026
  • PuTTY (Simon Tatham) — PuTTY SSH client (impersonated)
    Vulnerable versions: legitimate brand impersonated by Fox Tempest-signed trojanized installers
  • Cisco — Webex (impersonated)
    Vulnerable versions: legitimate brand impersonated by Fox Tempest-signed trojanized installers

Remediation for Fox Tempest Malware-Signing-as-a-Service (MSaaS)

Patches

  • No software patch — this is infrastructure abuse, not a software vulnerability. Apply Microsoft Defender signature updates released 2026-05-19 covering Oyster, Lumma, Vidar, Malcert, Rhysida, INC, Qilin, and BlackByte families.
  • Ensure Windows trust list updates (CTL) are pulling automatically so revoked Fox Tempest certificates are honored on endpoints.

Immediate actions

  • Block signspace[.]cloud at DNS, proxy, and perimeter firewall.
  • Add the two published SignerSha-1 thumbprints (dc0acb01e3086ea8a9cb144a5f97810d291020ce, 7e6d9dac619c04ae1b3c8c0906123e752ed66d63) to EDR/AV signer blocklists.
  • Retro-hunt EDR and disk imaging for SHA-256 f0668ce925f36ff7f3359b0ea47e3fa243af13cd6ad9661dfccc9ff79fb4f1cc.
  • Hunt last 12 months of execution telemetry for binaries with issuer 'Microsoft ID Verified CS EOC CA 01' and a leaf NotAfter-NotBefore delta <= 96 hours; treat as suspicious until attributed to a known ISV.
  • Block known masquerade-target lures: hunt for installer-named files (AnyDesk, Microsoft Teams, PuTTY, Webex) executed from user-writable paths (Downloads, Temp, AppData) with abnormal signer chains.
  • Enable Microsoft Defender 'cloud-delivered protection' and ensure ASR rule 'Use advanced protection against ransomware' is in Block mode.

Workarounds

  • If WDAC publisher allowlisting cannot be deployed immediately, deploy a deny-list of the two published SignerSha-1 thumbprints via WDAC FilePublisher rules or AppLocker Publisher Hash rules.
  • Force SmartScreen Block (not Warn) in Edge and Defender for Office 365.
  • Deny execution from %TEMP%, %APPDATA%, and Downloads via ASR rule 'Block executable content from email client and webmail' plus 'Block all Office applications from creating child processes.'

Longer-term hardening

  • Enforce WDAC or AppLocker publisher allowlisting against an explicit list of trusted ISVs by publisher CN, not against Microsoft chain trust alone — Microsoft Artifact Signing assigns chain trust to any onboarded tenant.
  • Deploy EDR with behavioral detection that does not down-weight on Authenticode signature trust for newly observed signers.
  • Block or sinkhole malvertising and SEO-poisoning landing pages by enforcing DNS/web filtering with reputation and newly registered domain (NRD) categories.
  • Restrict ad-supported web access on privileged workstations and on critical-asset operator endpoints.
  • Tenant-wide tamper protection enabled in Microsoft Defender to prevent ransomware operators from disabling controls post-execution.
  • Establish a signed-binary anomaly hunt that diffs publisher CN distribution week-over-week and alerts on first-seen Microsoft-chained publishers.
  • Train SOC analysts that Authenticode trust is not malware reputation: short-validity Microsoft-chained certificates require active verification of the named publisher.

Weaknesses (CWE) in Fox Tempest Malware-Signing-as-a-Service (MSaaS)

CWE-295, CWE-345, CWE-494, CWE-829

Timeline of Fox Tempest Malware-Signing-as-a-Service (MSaaS)

  • signspace[.]cloud first observed by Microsoft Threat Intelligence — Fox Tempest's MSaaS portal goes live offering fraudulent Microsoft Artifact Signing certificates to paying affiliates.
  • Vanilla Tempest (Rhysida operator) onboards as a Fox Tempest customer, beginning a campaign of trojanized Microsoft Teams installers signed with fraudulent Microsoft Artifact Signing certificates and distributed via purchased advertisements.
  • Microsoft Threat Intelligence formally opens a tracked-actor profile on Fox Tempest after correlating multiple incident-response engagements (Rhysida, INC, Qilin) sharing the 'Microsoft ID Verified CS EOC CA 01' issuer and short-lived 72h leaf certificates with synthetic publisher identities.
  • Storm-2561 leverages Fox Tempest signing service to distribute fake VPN clients via SEO poisoning, expanding the Fox Tempest customer footprint into infostealer (Lumma, Vidar) operations.
  • Fox Tempest migrates from direct portal upload to provisioning pre-configured US-based Cloudzy VPS for each customer — reducing operational friction and obscuring the portal-to-signing-tenant link. Example certificate validity observed February 19-22, 2026.
  • First observation of SignerSha-1 thumbprint dc0acb01e3086ea8a9cb144a5f97810d291020ce in customer-distributed binaries.
  • First observation of SHA-256 f0668ce925f36ff7f3359b0ea47e3fa243af13cd6ad9661dfccc9ff79fb4f1cc — a Fox Tempest-signed Vanilla Tempest payload.
  • First observation of SignerSha-1 thumbprint 7e6d9dac619c04ae1b3c8c0906123e752ed66d63 in customer-distributed binaries.
  • Last observation of Fox Tempest-signed SHA-256 f0668ce925f36ff7f3359b0ea47e3fa243af13cd6ad9661dfccc9ff79fb4f1cc.
  • signspace[.]cloud last observed active before disruption.
  • Last observation of Fox Tempest SignerSha-1 thumbprints (dc0acb01e3086ea8a9cb144a5f97810d291020ce, 7e6d9dac619c04ae1b3c8c0906123e752ed66d63) in the wild prior to revocation.
  • Microsoft Digital Crimes Unit disrupts Fox Tempest: revokes 1,000+ fraudulent code-signing certificates across hundreds of Azure tenants, takes down signspace[.]cloud, partners with Cloudzy to de-provision Fox Tempest-controlled VMs, and pushes Defender signature updates covering Oyster, Lumma, Vidar, Malcert, Rhysida, INC, Qilin, and BlackByte families plus a Vanilla Tempest activity-group profile.
  • As of 2026-05-29, Microsoft DCU's 2026-05-19 disruption (signspace[.]cloud sinkholed, 1,000+ certs revoked, Cloudzy VMs disabled) degraded but did not neutralize Fox Tempest. Microsoft confirms the actor is adapting and shifting operations/customers to another code-signing service, and downstream ransomware groups (Vanilla Tempest, Storm-0501) remain active, so MONITORING fits.

Sources cited for Fox Tempest Malware-Signing-as-a-Service (MSaaS)

More in malware

Detection coverage for TL-2026-0533

As of 2026-05-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0533 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats