Fox Tempest Malware-Signing-as-a-Service (MSaaS) — Microsoft DCU Disrupts signspace[.]cloud Operation Enabling Rhysida, INC, Qilin, Akira & Vanilla Tempest
Fox Tempest Malware-Signing-as-a-Service (MSaaS) (TL-2026-0533), also tracked as signspace.cloud operation, is a high-severity malware campaign, first published 2026-05-19. It is attributed to Fox Tempest (Russia) with medium confidence, affects Microsoft Microsoft Artifact Signing (Azure Trusted Signing), maps to 32 MITRE ATT&CK techniques (T1005, T1021.002, T1036.001), and is covered by 9 detection rules and 22 indicators of compromise.
Key facts for TL-2026-0533
- Threat ID
- TL-2026-0533
- Also known as
- signspace.cloud operation, MSaaS — Microsoft Artifact Signing abuse, SamCodeSign service
- Severity
- HIGH
- Status
- MONITORING
- Category
- MALWARE
- First published
- 2026-05-19
- Last reviewed
- 2026-05-19
- Attribution
- Fox Tempest
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- healthcare, education, government, financial-services
- Target regions
- United States, France, India, China
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in Fox Tempest Malware-Signing-as-a-Service (MSaaS)
Malware and tooling: AgendaCrypt, Akira, BlackByte, Broomstick, Lumma Stealer - S1213, Vidar, inc ransom, rhysida, Azure tenants/subscriptions registered with stolen US and Canada identities
Fox Tempest is a financially motivated, Russian-speaking criminal enterprise that operated signspace[.]cloud, a Malware-Signing-as-a-Service (MSaaS) platform that abused Microsoft Artifact Signing (formerly Azure Trusted Signing) to mint short-lived (72-hour) fraudulent code-signing certificates for paying ransomware and infostealer affiliates. Microsoft's Digital Crimes Unit (DCU) disrupted the operation on 2026-05-19 after eight months of tracking, revoking 1,000+ certificates across hundreds of Azure tenants and subscriptions registered with stolen US/Canadian identities. Customers — including Vanilla Tempest, Storm-0501, Storm-2561, and Storm-0249 — used Fox Tempest-signed binaries to deliver Rhysida, INC, Qilin, Akira, and BlackByte ransomware as well as Oyster (Broomstick), Lumma Stealer, and Vidar via SEO poisoning, malvertising, and trojanized installers masquerading as AnyDesk, Microsoft Teams, PuTTY, and Webex.
How Fox Tempest Malware-Signing-as-a-Service (MSaaS) works
Fox Tempest is the Microsoft Threat Intelligence cryptonym for a financially motivated, likely Russian-speaking cybercriminal group that built and operated a turnkey Malware-Signing-as-a-Service (MSaaS) platform hosted at signspace[.]cloud. The service was first offered in May 2025, picked up its first known affiliate customer (Vanilla Tempest) in June 2025, came under sustained Microsoft Threat Intelligence tracking in September 2025, and was disrupted by Microsoft DCU on 19 May 2026 — by which time over 1,000 fraudulent code-signing certificates had been issued through it.
The abuse target was Microsoft Artifact Signing (formerly Azure Trusted Signing), a cloud-managed signing service designed to give legitimate ISVs a Microsoft-rooted certificate chain (issuer 'Microsoft ID Verified CS EOC CA 01') with very short — 72 hour — leaf validity. Fox Tempest weaponized that design property: short-lived certs leave no useful long-lived revocation list to seed reputation systems on, while the chain to Microsoft's root made the signed binary appear high-trust to SmartScreen, EDR reputation lookups, application allowlisting (Software Restriction Policies, AppLocker, WDAC publisher rules), and analyst triage. To pass Trusted Signing identity validation, the operators acquired (very likely purchased on criminal markets) stolen identity documents from US- and Canada-based individuals and small businesses, used those identities to stand up hundreds of Azure tenants and subscriptions, and onboarded each to Trusted Signing as a separate 'publisher.' Each tenant became a disposable signing oracle: a customer's PE file went in, came back signed by a Microsoft-rooted leaf cert tied to a synthetic 'publisher' identity, and was burned within 72 hours.
The customer-facing portal at signspace[.]cloud was a full SaaS offering: an admin panel managing tooling and customer accounts, a customer upload interface for unsigned malicious binaries, a structured backend database tracking users and submissions, and configuration files linked to a GitHub repository named 'code-signing-service.' From May 2025 through February 2026 customers uploaded binaries directly through the web portal. From February 2026 onward, Fox Tempest matured the offering: customers were provisioned a pre-configured US-based Cloudzy VPS that handled upload, signing, and return of the binary, reducing operational friction and obscuring the link between portal and signing tenant. Pricing was tiered between USD 5,000 and USD 9,000 via a Google Form, with higher-paying customers receiving signing-queue priority. Sales and support were brokered on Telegram under the handle @arbadakarba2000 (channel name 'EV Certs for Sale by SamCodeSign'). Operator-facing documentation was bilingual English/Russian — the primary linguistic attribution signal — and cryptocurrency tracing tied wallets to known ransomware affiliate clusters, supporting the assessment that Fox Tempest is a well-resourced criminal enterprise with dedicated roles for infrastructure, customer ops, and finance.
Downstream impact spanned the top tier of the criminal ransomware ecosystem. Vanilla Tempest (the Rhysida operator) used Fox Tempest signatures from June 2025 onward to sign trojanized Microsoft Teams installers delivered via purchased Google/Bing advertisements; the loader stage was Oyster/Broomstick, terminating in Rhysida deployment. Storm-2561 used Fox Tempest-signed fake VPN clients distributed via SEO poisoning. Storm-0501 and Storm-0249 used Fox Tempest signatures across active intrusions ending in INC, Qilin, Akira, and BlackByte ransomware. Infostealer affiliates used the signing service to push Lumma Stealer and Vidar past SmartScreen and reputation gates. Microsoft estimates extortion proceeds attributable to Fox Tempest-signed campaigns 'in the millions' of US dollars, with confirmed victims across healthcare, education, government, and financial services in the United States, France, India, and China.
The full exploit chain, end to end: (1) An affiliate procures a binary (loader, dropper, or stage-two implant) and uploads it through signspace[.]cloud or the Cloudzy VM. (2) Fox Tempest's backend selects an unburned Azure tenant — registered with a stolen US/Canada identity and onboarded to Microsoft Artifact Signing — and submits a signing request, which Microsoft Artifact Signing fulfills against that tenant's policy. (3) A short-lived (72h) leaf certificate chained to 'Microsoft ID Verified CS EOC CA 01' is bound to the binary, which is returned to the customer. (4) The customer distributes the signed binary via SEO poisoning (typosquatted or SEO-stuffed download pages ranking for 'anydesk download,' 'putty,' 'webex installer,' 'microsoft teams,' free VPN clients) and/or malvertising (purchased Google Ads and Bing Ads redirecting through cloaked affiliate networks to the fake download). (5) Victim downloads, sees a Microsoft-rooted publisher signature, and runs the installer. (6) Loader (Oyster/Broomstick, or a stealer dropper) executes; Defender SmartScreen and many EDR reputation engines treat the binary as trusted on signature. (7) For ransomware tracks, the loader fetches second-stage tooling (Cobalt Strike, Sliver, or operator-specific implants), performs discovery and credential access, moves laterally, exfiltrates data, and detonates Rhysida/INC/Qilin/Akira/BlackByte. For stealer tracks, Lumma or Vidar harvests credentials, cookies, MFA tokens, and crypto wallets and exfiltrates to operator C2.
The Microsoft DCU disruption on 2026-05-19 included: revocation of 1,000+ certificates issued through Fox Tempest tenants, takedown of signspace[.]cloud, coordination with Cloudzy to identify and de-provision Fox Tempest-controlled VMs, and Defender signature pushes covering Oyster, Lumma, Vidar, Malcert, Rhysida, INC, Qilin, and BlackByte family detections plus a Vanilla Tempest activity-group profile. Defenders should treat any binary with a 'Microsoft ID Verified CS EOC CA 01' leaf signature between May 2025 and May 2026 as potentially abused unless explicitly attributable to a known legitimate ISV. Hunt for the published SignerSha-1 thumbprints, retro-hunt on the SHA-256, and audit signed-binary execution from user-writable paths and recent download locations. Long-term defenders should enforce publisher allowlisting (WDAC) against an explicit list of trusted publishers rather than relying on Microsoft chain trust alone, since Microsoft Artifact Signing assigns chain trust to any onboarded tenant.
MITRE ATT&CK techniques used in TL-2026-0533
Collection
Lateral Movement
T1021.002 Remote Services: SMB/Windows Admin Shares
Defense Evasion
T1036.001 Invalid Code Signature; T1036.005 Match Legitimate Resource Name or Location; T1070.004 Indicator Removal: File Deletion
Exfiltration
T1041 Exfiltration Over C2 Channel
Discovery
T1057 Process Discovery; T1082 System Information Discovery
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1204.002 User Execution: Malicious File
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1105 Ingress Tool Transfer
Initial Access
T1189 Drive-by Compromise; T1566.002 Phishing: Spearphishing Link
Impact
T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery
Credential Access
T1539 Steal Web Session Cookie; T1555.003 Credentials from Password Stores: Credentials from Web Browsers
Persistence
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
defense-impairment
T1553.002 Subvert Trust Controls: Code Signing; T1553.003 Subvert Trust Controls: SIP and Trust Provider Hijacking; T1685 Disable or Modify Tools
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1583.003 Acquire Infrastructure: Virtual Private Server; T1583.006 Acquire Infrastructure: Web Services; T1585.003 Establish Accounts: Cloud Accounts; T1586.002 Email Accounts; T1588.003 Obtain Capabilities: Code Signing Certificates; T1588.004 Obtain Capabilities: Digital Certificates; T1608.001 Stage Capabilities: Upload Malware; T1608.004 Stage Capabilities: Drive-by Target; T1608.006 Stage Capabilities: SEO Poisoning
Affected products and versions in Fox Tempest Malware-Signing-as-a-Service (MSaaS)
- Microsoft — Microsoft Artifact Signing (Azure Trusted Signing)
Vulnerable versions: service-wide identity-validation bypass via stolen US/Canada identities, 2025-05 through 2026-05
Fixed in: 1,000+ certificates revoked 2026-05-19; identity validation hardening per Microsoft DCU disruption - Microsoft — Windows code-signing trust chain (Microsoft ID Verified CS EOC CA 01)
Vulnerable versions: any Windows host treating Microsoft-rooted Authenticode signatures as high-reputation 2025-05 through 2026-05
Fixed in: Defender signatures updated 2026-05-19; SmartScreen/MAPS reputation updated; revoked thumbprints distributed via Windows CTL - AnyDesk — AnyDesk Remote Desktop (impersonated)
Vulnerable versions: legitimate brand impersonated by Fox Tempest-signed trojanized installers - Microsoft — Microsoft Teams (impersonated)
Vulnerable versions: legitimate brand impersonated by Vanilla Tempest using Fox Tempest signatures, June 2025-May 2026 - PuTTY (Simon Tatham) — PuTTY SSH client (impersonated)
Vulnerable versions: legitimate brand impersonated by Fox Tempest-signed trojanized installers - Cisco — Webex (impersonated)
Vulnerable versions: legitimate brand impersonated by Fox Tempest-signed trojanized installers
Remediation for Fox Tempest Malware-Signing-as-a-Service (MSaaS)
Patches
- No software patch — this is infrastructure abuse, not a software vulnerability. Apply Microsoft Defender signature updates released 2026-05-19 covering Oyster, Lumma, Vidar, Malcert, Rhysida, INC, Qilin, and BlackByte families.
- Ensure Windows trust list updates (CTL) are pulling automatically so revoked Fox Tempest certificates are honored on endpoints.
Immediate actions
- Block signspace[.]cloud at DNS, proxy, and perimeter firewall.
- Add the two published SignerSha-1 thumbprints (dc0acb01e3086ea8a9cb144a5f97810d291020ce, 7e6d9dac619c04ae1b3c8c0906123e752ed66d63) to EDR/AV signer blocklists.
- Retro-hunt EDR and disk imaging for SHA-256 f0668ce925f36ff7f3359b0ea47e3fa243af13cd6ad9661dfccc9ff79fb4f1cc.
- Hunt last 12 months of execution telemetry for binaries with issuer 'Microsoft ID Verified CS EOC CA 01' and a leaf NotAfter-NotBefore delta <= 96 hours; treat as suspicious until attributed to a known ISV.
- Block known masquerade-target lures: hunt for installer-named files (AnyDesk, Microsoft Teams, PuTTY, Webex) executed from user-writable paths (Downloads, Temp, AppData) with abnormal signer chains.
- Enable Microsoft Defender 'cloud-delivered protection' and ensure ASR rule 'Use advanced protection against ransomware' is in Block mode.
Workarounds
- If WDAC publisher allowlisting cannot be deployed immediately, deploy a deny-list of the two published SignerSha-1 thumbprints via WDAC FilePublisher rules or AppLocker Publisher Hash rules.
- Force SmartScreen Block (not Warn) in Edge and Defender for Office 365.
- Deny execution from %TEMP%, %APPDATA%, and Downloads via ASR rule 'Block executable content from email client and webmail' plus 'Block all Office applications from creating child processes.'
Longer-term hardening
- Enforce WDAC or AppLocker publisher allowlisting against an explicit list of trusted ISVs by publisher CN, not against Microsoft chain trust alone — Microsoft Artifact Signing assigns chain trust to any onboarded tenant.
- Deploy EDR with behavioral detection that does not down-weight on Authenticode signature trust for newly observed signers.
- Block or sinkhole malvertising and SEO-poisoning landing pages by enforcing DNS/web filtering with reputation and newly registered domain (NRD) categories.
- Restrict ad-supported web access on privileged workstations and on critical-asset operator endpoints.
- Tenant-wide tamper protection enabled in Microsoft Defender to prevent ransomware operators from disabling controls post-execution.
- Establish a signed-binary anomaly hunt that diffs publisher CN distribution week-over-week and alerts on first-seen Microsoft-chained publishers.
- Train SOC analysts that Authenticode trust is not malware reputation: short-validity Microsoft-chained certificates require active verification of the named publisher.
Weaknesses (CWE) in Fox Tempest Malware-Signing-as-a-Service (MSaaS)
CWE-295, CWE-345, CWE-494, CWE-829
Timeline of Fox Tempest Malware-Signing-as-a-Service (MSaaS)
- signspace[.]cloud first observed by Microsoft Threat Intelligence — Fox Tempest's MSaaS portal goes live offering fraudulent Microsoft Artifact Signing certificates to paying affiliates.
- Vanilla Tempest (Rhysida operator) onboards as a Fox Tempest customer, beginning a campaign of trojanized Microsoft Teams installers signed with fraudulent Microsoft Artifact Signing certificates and distributed via purchased advertisements.
- Microsoft Threat Intelligence formally opens a tracked-actor profile on Fox Tempest after correlating multiple incident-response engagements (Rhysida, INC, Qilin) sharing the 'Microsoft ID Verified CS EOC CA 01' issuer and short-lived 72h leaf certificates with synthetic publisher identities.
- Storm-2561 leverages Fox Tempest signing service to distribute fake VPN clients via SEO poisoning, expanding the Fox Tempest customer footprint into infostealer (Lumma, Vidar) operations.
- Fox Tempest migrates from direct portal upload to provisioning pre-configured US-based Cloudzy VPS for each customer — reducing operational friction and obscuring the portal-to-signing-tenant link. Example certificate validity observed February 19-22, 2026.
- First observation of SignerSha-1 thumbprint dc0acb01e3086ea8a9cb144a5f97810d291020ce in customer-distributed binaries.
- First observation of SHA-256 f0668ce925f36ff7f3359b0ea47e3fa243af13cd6ad9661dfccc9ff79fb4f1cc — a Fox Tempest-signed Vanilla Tempest payload.
- First observation of SignerSha-1 thumbprint 7e6d9dac619c04ae1b3c8c0906123e752ed66d63 in customer-distributed binaries.
- Last observation of Fox Tempest-signed SHA-256 f0668ce925f36ff7f3359b0ea47e3fa243af13cd6ad9661dfccc9ff79fb4f1cc.
- signspace[.]cloud last observed active before disruption.
- Last observation of Fox Tempest SignerSha-1 thumbprints (dc0acb01e3086ea8a9cb144a5f97810d291020ce, 7e6d9dac619c04ae1b3c8c0906123e752ed66d63) in the wild prior to revocation.
- Microsoft Digital Crimes Unit disrupts Fox Tempest: revokes 1,000+ fraudulent code-signing certificates across hundreds of Azure tenants, takes down signspace[.]cloud, partners with Cloudzy to de-provision Fox Tempest-controlled VMs, and pushes Defender signature updates covering Oyster, Lumma, Vidar, Malcert, Rhysida, INC, Qilin, and BlackByte families plus a Vanilla Tempest activity-group profile.
- As of 2026-05-29, Microsoft DCU's 2026-05-19 disruption (signspace[.]cloud sinkholed, 1,000+ certs revoked, Cloudzy VMs disabled) degraded but did not neutralize Fox Tempest. Microsoft confirms the actor is adapting and shifting operations/customers to another code-signing service, and downstream ransomware groups (Vanilla Tempest, Storm-0501) remain active, so MONITORING fits.
Sources cited for Fox Tempest Malware-Signing-as-a-Service (MSaaS)
- Exposing Fox Tempest: A malware-signing service operation
- Microsoft Trusted Signing — Service Overview
- Microsoft Digital Crimes Unit
- Vanilla Tempest activity group profile (Rhysida operator)
- Rhysida Ransomware — CISA #StopRansomware Advisory AA23-319A
- MITRE ATT&CK T1553.002 — Subvert Trust Controls: Code Signing
- MITRE ATT&CK T1583.003 — Acquire Infrastructure: Virtual Private Server
- MITRE ATT&CK T1608.005 — Stage Capabilities: Link Target (SEO poisoning context)
- Oyster (Broomstick) backdoor analysis
- Lumma Stealer technical overview
- Cloudzy abuse reporting (Halcyon)
More in malware
- MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana Blockchain for C2
- AI-Powered Polymorphic Malware Queries LLMs at Runtime to Evade Signature Detection: PROMPTFLUX and PROMPTSTEAL/LAMEHUG (APT28)
- EtherHiding / Blockchain Dead Drops: Nation-State Actors Drive 440% Surge in On-Chain Malware C2
- KREMLIN Banking Malware Forges Chrome/Edge Secure Preferences Integrity Checks to Force-Install Malicious 'AVSync' Extension
- Iranian State Actors Deploy CHOSEN BRICK Windows Malware to Spy on Dissidents, Activists, and Journalists
Detection coverage for TL-2026-0533
As of 2026-05-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0533 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.