threat-intel
Cybercrime service disrupted for abusing Microsoft platform to sign malware
High
Summary
Microsoft disrupted a malware-as-a-service (MaaS) operation, dubbed Fox Tempest, that was abusing its Artifact Signing service to generate fraudulent code-signing certificates for ransomware gangs and other cybercriminals. The operation, which involved over 1,000 certificates and hundreds of Azure tenants, was used to sign malicious software like Oyster and Rhysida, allowing attackers to bypass security controls. Microsoft seized the signspace[.]cloud domain and offline hundreds of virtual machines as part of a legal action targeting the scheme.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data