By David Jones
Publication Date: 2026-05-20 10:48:00
This story was originally published on Cybersecurity Dive. To receive daily news and insights, subscribe to our free daily Cybersecurity Dive newsletter.
Microsoft on Tuesday said it disrupted Fox Tempest, a cybercrime operation that helped ransomware gangs hide malware behind legitimate software.
Fox Tempest operated a malware signing-as-a-service operation, which abused code-signing tools that verify the authenticity of commercial software.
Ransomware gangs and other criminal actors abused tools, including Microsoft’s Artifact Signing, to deliver malware as part of a wider campaign to launch ransomware attacks.
Through a legal filing with the U.S. District Court for the Southern District of New York, Microsoft was able to disrupt the Fox Tempest website, take hundreds of virtual machines offline and block access to a website that hosted the operation’s underlying code.
The legal filing also named the Vanilla Tempest ransomware group as a co-conspirator. Vanilla Tempest…

