news.mlab.sh
Back to the feed
threat-intel

Cybercrime service disrupted for abusing Microsoft platform to sign malware

High
Summary

Microsoft disrupted a malware-as-a-service (MaaS) operation, dubbed Fox Tempest, that was abusing its Artifact Signing service to generate fraudulent code-signing certificates for ransomware gangs and other cybercriminals. The operation, which involved over 1,000 certificates and hundreds of Azure tenants, was used to sign malicious software like Oyster and Rhysida, allowing attackers to bypass security controls. Microsoft seized the signspace[.]cloud domain and offline hundreds of virtual machines as part of a legal action targeting the scheme.

Read the full article at BleepingComputer

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.