Fox Tempest Malware-Signing-as-a-Service (MSaaS) — Microsoft DCU Disrupts signspace[.]cloud Operation Enabling Rhysida, INC, Qilin, Akira & Vanilla Tempest — Threadlinqs Intelligence
As of 2026-05-30, Fox Tempest Malware-Signing-as-a-Service (MSaaS) — Microsoft DCU Disrupts signspace[.]cloud Operation Enabling Rhysida, INC, Qilin, Akira & Vanilla Tempest is a high-severity malware threat attributed to Fox Tempest (Russia (suspected, language-based attribution)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 22 indicators of compromise.
Threat ID: TL-2026-0533 · Severity: HIGH · Status: MONITORING · Category: MALWARE
Attribution: Fox Tempest · Russia (suspected, language-based attribution) · FINANCIAL
Fox Tempest is a financially motivated, Russian-speaking criminal enterprise that operated signspace[.]cloud, a Malware-Signing-as-a-Service (MSaaS) platform that abused Microsoft Artifact Signing
Fox Tempest is the Microsoft Threat Intelligence cryptonym for a financially motivated, likely Russian-speaking cybercriminal group that built and operated a turnkey Malware-Signing-as-a-Service (MSaaS) platform hosted at signspace[.]cloud. The service was first offered in May 2025, picked up its first known affiliate customer (Vanilla Tempest) in June 2025, came under sustained Microsoft Threat Intelligence tracking in September 2025, and was disrupted by Microsoft DCU on 19 May 2026 — by which time over 1,000 fraudulent code-signing certificates had been issued through it.
The abuse target was Microsoft Artifact Signing (formerly Azure Trusted Signing), a cloud-managed signing service designed to give legitimate ISVs a Microsoft-rooted certificate chain (issuer 'Microsoft ID Verified CS EOC CA 01') with very short — 72 hour — leaf validity. Fox Tempest weaponized that design property: short-lived certs leave no useful long-lived revocation list to seed reputation systems on, while the chain to Microsoft's root made the signed binary appear high-trust to SmartScreen, EDR reputation lookups, application allowlisting (Software Restriction Policies, AppLocker, WDAC publisher rules), and analyst triage. To pass Trusted Signing identity validation, the operators acquired (very likely purchased on criminal markets) stolen identity documents from US- and Canada-based individuals and small businesses, used those identities to stand up hundreds of Azure tenants and subscriptions, and onboarded each to Trusted Signing as a separate 'publisher.' Each tenant became a disposable signing oracle: a customer's PE file went in, came back signed by a Microsoft-rooted leaf cert tied to a synthetic 'publisher' identity, and was burned within 72 hours.
The customer-facing portal at signspace[.]cloud was a full SaaS offering: an admin panel managing tooling and customer accounts, a customer upload interface for unsigned malicious binaries, a structured backend database tracking users and submissions, and configuration files linked to a GitHub repository named 'code-signing-service.' From May 2025 through February 2026 customers uploaded binaries directly through the web portal. From February 2026 onward, Fox Tempest matured the offering: customers were provisioned a pre-configured US-based Cloudzy VPS that handled upload, signing, and return of the binary, reducing operational friction and obscuring the link between portal and signing tenant. Pricing was tiered between USD 5,000 and USD 9,000 via a Google Form, with higher-paying customers receiving signing-queue priority. Sales and support were brokered on Telegram under the handle @arbadakarba2000 (channel name 'EV Certs for Sale by SamCodeSign'). Operator-facing documentation was bilingual English/Russian — the primary linguistic attribution signal — and cryptocurrency tracing tied wallets to known ransomware affiliate clusters, supporting the assessment that Fox Tempest is a well-resourced criminal enterprise with dedicated roles for infrastructure, customer ops, and finance.
Downstream impact spanned the top tier of the criminal ransomware ecosystem. Vanilla Tempest (the Rhysida operator) used Fox Tempest signatures from June 2025 onward to sign trojanized Microsoft Teams installers delivered via purchased Google/Bing advertisements; the loader stage was Oyster/Broomstick, terminating in Rhysida deployment. Storm-2561 used Fox Tempest-signed fake VPN clients distributed via SEO poisoning. Storm-0501 and Storm-0249 used Fox Tempest signatures across active intrusions ending in INC, Qilin, Akira, and BlackByte ransomware. Infostealer affiliates used the signing service to push Lumma Stealer and Vidar past SmartScreen and reputation gates. Microsoft estimates extortion proceeds attributable to Fox Tempest-signed campaigns 'in the millions' of US dollars, with confirmed victims across healthcare, education, government, and financial services in the United States, France, India, and China.
The
Weaknesses (CWE)
CWE-295, CWE-345, CWE-494, CWE-829
Target sectors: healthcare, education, government, financial-services
Target regions: United States, France, India, China
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 22 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583.001, T1583.003, T1583.006, T1585.003, T1588.003, T1588.004, T1608.001, T1608.006, T1608.004, T1586.002