threat-intel
Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks
High
Summary
Microsoft disrupted a malware-signing-as-a-service (MSaaS) operation, dubbed OpFauxSign, led by the threat actor Fox Tempest, which was using its Artifact Signing system to distribute malware and ransomware. The operation targeted thousands of machines globally and involved the deployment of ransomware families like Rhysida, Oyster, and Lumma Stealer, alongside connections to groups like Vanilla Tempest and INC. Microsoft’s response involved seizing the signspace[.]cloud website and offline virtual machines, highlighting the importance of securing code-signing services.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
