As cited
Copy frozen at (site build).
ransomware
Risky Bulletin: Microsoft takes down MSaaS used by ransomware gangs
Microsoft disrupted SignSpaceCloud, a Russian malware-signing-as-a-service (MSaaS) operation tracked as Fox Tempest, by taking legal action and seizing its infrastructure. The service had been generating fraudulent code signing certificates through hundreds of fake Microsoft Artifact Signing accounts and reselling them to ransomware and malware developers. Fox Tempest monetized these certificates by charging thousands of dollars per certificate to threat actors.
Why it matters: Organizations and defenders need to monitor for malware and ransomware signed with certificates from this service, as legitimate-looking signatures increase infection success rates and complicate detection.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
Risky Bulletin: Microsoft takes down MSaaS used by ransomware gangs
Microsoft disrupted SignSpaceCloud, a Russian malware-signing-as-a-service (MSaaS) operation tracked as Fox Tempest, by taking legal action and seizing its infrastructure. The service had been generating fraudulent code signing certificates through hundreds of fake Microsoft Artifact Signing accounts and reselling them to ransomware and malware developers. Fox Tempest monetized these certificates by charging thousands of dollars per certificate to threat actors.
Why it matters: Organizations and defenders need to monitor for malware and ransomware signed with certificates from this service, as legitimate-looking signatures increase infection success rates and complicate detection.
- Source published
- First seen by Cybersecurity Tracker