CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Risky Bulletin: Microsoft takes down MSaaS used by ransomware gangs

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 187

As cited

Copy frozen at (site build).

ransomware

Risky Bulletin: Microsoft takes down MSaaS used by ransomware gangs

Microsoft disrupted SignSpaceCloud, a Russian malware-signing-as-a-service (MSaaS) operation tracked as Fox Tempest, by taking legal action and seizing its infrastructure. The service had been generating fraudulent code signing certificates through hundreds of fake Microsoft Artifact Signing accounts and reselling them to ransomware and malware developers. Fox Tempest monetized these certificates by charging thousands of dollars per certificate to threat actors.

Why it matters: Organizations and defenders need to monitor for malware and ransomware signed with certificates from this service, as legitimate-looking signatures increase infection success rates and complicate detection.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Risky Bulletin: Microsoft takes down MSaaS used by ransomware gangs

Microsoft disrupted SignSpaceCloud, a Russian malware-signing-as-a-service (MSaaS) operation tracked as Fox Tempest, by taking legal action and seizing its infrastructure. The service had been generating fraudulent code signing certificates through hundreds of fake Microsoft Artifact Signing accounts and reselling them to ransomware and malware developers. Fox Tempest monetized these certificates by charging thousands of dollars per certificate to threat actors.

Why it matters: Organizations and defenders need to monitor for malware and ransomware signed with certificates from this service, as legitimate-looking signatures increase infection success rates and complicate detection.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary