Historical intelligence backfill. This assessment covers reporting originally published on 2026-05-19 and was added to the RWP archive on 2026-09-07.

Daily Top · Supply Chain

Fox Tempest sold 72-hour Microsoft signatures so ransomware looked like AnyDesk

Microsoft DCU seized signspace.cloud, revoked 1,000-plus Artifact Signing certs, and sued a malware-signing-as-a-service used by Vanilla Tempest / Rhysida, Qilin, Akira, and INC.

RWP Ventures · 2026-09-07 · event 2026-05-19 · 2 min read · priority 8.5

Bottom line up front

CONFIRMED On 19 May 2026 Microsoft unsealed SDNY action against Fox Tempest, a financially motivated actor running malware-signing-as-a-service since about May 2025. Customers uploaded binaries; Fox Tempest abused Microsoft Artifact Signing (formerly Azure Trusted Signing) for short-lived (~72 hour) certs. Microsoft: 1,000-plus certificates, hundreds of Azure tenants, later Cloudzy VMs; DCU seized signspace[.]cloud, took VMs offline, revoked certs. Named consumer: Vanilla Tempest (Oyster, Lumma, Vidar, Rhysida). Secondary reporting also names INC, Qilin, Akira as customers and quotes expedite pricing in the $5k–$9.5k range. Signed fakes included AnyDesk, Teams, PuTTY, Webex-style installers.

Historical backfill of 19 May 2026 reporting; added 7 September 2026.

What happened

Trust in Authenticode is a market. When Microsoft raised friction, Fox Tempest moved from self-serve portal to hosted VMs. Criminals on forums complained after the seizure — a useful impact metric.

Why it mattered

Allow-listing "signed Microsoft-issued" is not a control if the tenant that requested the cert was fake. SmartScreen and reputation lose.

Who / what was affected

Windows enterprises that execute signed remote-support tools; ransomware victims of named families. OT: UNKNOWN unless a specific plant used a signed fake RMM — not in these sources.

Technical context

Prefer publisher pinning to your vendors, not "any Microsoft-signed blob." Hunt recently issued, short-lived Artifact Signing certs on unexpected binaries.

Exploitation / threat status at the time

CONFIRMED Microsoft legal/technical disruption.

REPORTED customer list beyond Vanilla Tempest and price list.

What defenders should have done

  1. Block unexpected remote-admin installers even if signed.
  2. Revoke/trust-break on Microsoft's revoked serials.
  3. Assume Oyster/Lumma if a "Teams installer" arrived from ads.

RWP assessment

Confidence: High on the service and seizure. Signing-as-a-service will reappear under another shop.

Defensive actions

  1. Application control by publisher and product, not Authenticode alone.
  2. Subscribe to Microsoft revoked-cert updates.
  3. User rule: never install AnyDesk/Teams from a search ad.

Sources

  1. Microsoft Threat Intelligence — Exposing Fox Tempest malware-signing service
  2. Microsoft On the Issues — Disrupting Fox Tempest
  3. Malwarebytes — Fake malware-signing service Fox Tempest dismantled