Fox Tempest is a financially motivated cybercriminal group known for operating a malware-signing-as-a-service (MSaaS) to sign malware as trusted software.
Analyst brief
Fox Tempest is a financially motivated cybercriminal group primarily operating a malware-signing-as-a-service (MSaaS) to help other criminals sign malware, including ransomware, as trusted software. Their key TTPs involve abusing Microsoft Artifact Signing to issue short-lived fraudulent code-signing certificates, which were then used to distribute malware families such as Oyster, Lumma Stealer, and Vidar. Defenders should enhance monitoring for suspiciously signed software, particularly files with short-lived but trusted certificates, and focus on blocking network traffic associated with the domains used for certificate issuance, such as signspace[.]cloud.
Fox Tempest
unknown
Fox Tempest is a financially motivated threat actor that operated a malware-signing-as-a-service (MSaaS) sold to other cybercriminals to sign malware, including ransomware, as trusted software and evade detection. The service, marketed through the domain signspace[.]cloud and a Telegram channel, abused Microsoft Artifact Signing to issue short-lived fraudulent code-signing certificates and offered signing plans priced between 5,000 and 9,000 USD, with higher tiers providing pre-configured virtual machines for signing malicious code. Microsoft tracked the operation from September 2025 and observed its certificates used to distribute malware families such as Oyster, Lumma Stealer, and Vidar and to support ransomware activity linked to Vanilla Tempest, Storm-0501, Storm-2561, and Storm-0249. In May 2026, Microsoft's Digital Crimes Unit disrupted the operation, seizing signspace[.]cloud, taking hundreds of signing virtual machines offline, and revoking more than 1,000 fraudulent certificates, and named Vanilla Tempest as a co-defendant in a case filed in the U.S. District Court for the Southern District of New York.
What primary service does the Fox Tempest group provide?+
Fox Tempest is a financially motivated cybercriminal group that primarily operates a malware-signing-as-a-service (MSaaS) to help other criminals sign malware, including ransomware, as trusted software.
What is the primary technique Fox Tempest uses to create certificates?+
Fox Tempest's key TTPs involve abusing Microsoft Artifact Signing to issue short-lived fraudulent code-signing certificates.