Historical intelligence backfill. This assessment covers reporting originally published on 2026-05-19 and was added to the RWP archive on 2026-09-07.
Fox Tempest sold 72-hour Microsoft signatures so ransomware looked like AnyDesk
Microsoft DCU seized signspace.cloud, revoked 1,000-plus Artifact Signing certs, and sued a malware-signing-as-a-service used by Vanilla Tempest / Rhysida, Qilin, Akira, and INC.
Bottom line up front
CONFIRMED On 19 May 2026 Microsoft unsealed SDNY action against Fox Tempest, a financially motivated actor running malware-signing-as-a-service since about May 2025. Customers uploaded binaries; Fox Tempest abused Microsoft Artifact Signing (formerly Azure Trusted Signing) for short-lived (~72 hour) certs. Microsoft: 1,000-plus certificates, hundreds of Azure tenants, later Cloudzy VMs; DCU seized signspace[.]cloud, took VMs offline, revoked certs. Named consumer: Vanilla Tempest (Oyster, Lumma, Vidar, Rhysida). Secondary reporting also names INC, Qilin, Akira as customers and quotes expedite pricing in the $5k–$9.5k range. Signed fakes included AnyDesk, Teams, PuTTY, Webex-style installers.
Historical backfill of 19 May 2026 reporting; added 7 September 2026.
What happened
Trust in Authenticode is a market. When Microsoft raised friction, Fox Tempest moved from self-serve portal to hosted VMs. Criminals on forums complained after the seizure — a useful impact metric.
Why it mattered
Allow-listing "signed Microsoft-issued" is not a control if the tenant that requested the cert was fake. SmartScreen and reputation lose.
Who / what was affected
Windows enterprises that execute signed remote-support tools; ransomware victims of named families. OT: UNKNOWN unless a specific plant used a signed fake RMM — not in these sources.
Technical context
Prefer publisher pinning to your vendors, not "any Microsoft-signed blob." Hunt recently issued, short-lived Artifact Signing certs on unexpected binaries.
Exploitation / threat status at the time
CONFIRMED Microsoft legal/technical disruption.
REPORTED customer list beyond Vanilla Tempest and price list.
What defenders should have done
- Block unexpected remote-admin installers even if signed.
- Revoke/trust-break on Microsoft's revoked serials.
- Assume Oyster/Lumma if a "Teams installer" arrived from ads.
RWP assessment
Confidence: High on the service and seizure. Signing-as-a-service will reappear under another shop.
Defensive actions
- Application control by publisher and product, not Authenticode alone.
- Subscribe to Microsoft revoked-cert updates.
- User rule: never install AnyDesk/Teams from a search ad.
Sources
- Microsoft Threat Intelligence — Exposing Fox Tempest malware-signing service
- Microsoft On the Issues — Disrupting Fox Tempest
- Malwarebytes — Fake malware-signing service Fox Tempest dismantled