---
schema: 1
kind: threat
title: "Microsoft DCU disrupts Fox Tempest malware-signing-as-a-service feeding Rhysida, INC, Qilin and Akira ransomware operations"
headline: "Microsoft DCU disrupts Fox Tempest malware-signing-as-a-service feeding Rhysida, INC, Qilin and Akira ransomware operations"
summary: "Microsoft Digital Crimes Unit disrupts Fox Tempest malware-signing-as-a-service. 1,000+ fraudulent short-lived Microsoft Artifact Signing certificates revoked; signspace[.]cloud seized via SDNY court order. Downstream customers include Vanilla Tempest (Rhysida), Storm-0501, Storm-2561, Storm-0249; ransomware families served include Rhysida, INC, Qilin, Akira (Microsoft Threat Intelligence, 2026-05-19). Detection: hunt for Microsoft-signed PE binaries with cert validity ≤72h from Trusted Signing issuers."
discovered_at: "2026-05-20T05:00:01Z"
event_date: 2026-05-19
run_id: 2026-05-20-a0f7b07f
priority: high
immediate_action: null
tags:
  - ransomware
  - supply-chain
  - law-enforcement
  - organized-crime
  - identity
regions:
  - global
  - europe
  - us
sectors:
  - healthcare
  - education
  - public-sector
  - finance
entities:
  - "actor:fox-tempest"
  - "actor:akira"
  - "actor:qilin"
cves: []
sources:
  - url: "https://www.microsoft.com/en-us/security/blog/2026/05/19/exposing-fox-tempest-a-malware-signing-service-operation/"
    publisher: "Microsoft Threat Intelligence — Exposing Fox Tempest, 2026-05-19"
    role: primary
  - url: "https://blogs.microsoft.com/on-the-issues/2026/05/19/disrupting-fox-tempest-a-cybercrime-service/"
    publisher: "Microsoft On the Issues — DCU legal action, 2026-05-19"
    role: corroborating
  - url: "https://therecord.media/microsoft-disrupts-fox-tempest-malware-signing-service"
    publisher: "The Record, 2026-05-19"
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-05-20.md
---

Microsoft Threat Intelligence published a detailed exposure of "Fox Tempest" on [2026-05-19](https://www.microsoft.com/en-us/security/blog/2026/05/19/exposing-fox-tempest-a-malware-signing-service-operation/), concurrent with the Microsoft Digital Crimes Unit unsealing a U.S. District Court (SDNY) civil action and seizing the signspace[.]cloud infrastructure ([The Record, 2026-05-19](https://therecord.media/microsoft-disrupts-fox-tempest-malware-signing-service)). The actor operated a malware-signing-as-a-service (MSaaS) since at least May 2025, abusing **Microsoft Artifact Signing** (formerly Azure Trusted Signing) to mint short-lived (72-hour) code-signing certificates tied to stolen US and Canadian identities ([Microsoft Threat Intelligence](https://www.microsoft.com/en-us/security/blog/2026/05/19/exposing-fox-tempest-a-malware-signing-service-operation/)). Customers uploaded malicious binaries — masquerading as AnyDesk, Teams, PuTTY, Webex — and received Microsoft-signed executables that bypassed AV/EDR signing checks. Microsoft's write-up details the service's commercialisation: short-lived signing certificates sold to ransomware affiliates per signing run, with infrastructure transitioning in February 2026 to VM-based delivery on Cloudzy-hosted hosts that accepted customer binaries and returned signed outputs.

Confirmed downstream customers: **Vanilla Tempest** (deploying Rhysida ransomware via Microsoft-signed `MSTeamsSetup.exe` carrying the Oyster/Broomstick backdoor), **Storm-0501**, **Storm-2561**, **Storm-0249**, and ransomware families **Rhysida**, **INC**, **Qilin**, **Akira**, plus commodity loaders **Oyster**, **Lumma Stealer**, and **Vidar**. Microsoft revoked 1,000+ fraudulent code-signing certificates, disabled hundreds of Cloudzy-hosted VMs that Fox Tempest used as its delivery surface, and rolled identity-validation controls into Artifact Signing. Microsoft's blog notes confirmed affected sectors include healthcare, education, government, and financial services across the US, **France**, India, and China.

**Why it matters to us:** European public-sector and healthcare organisations are explicit downstream victims of the affiliates Fox Tempest serviced (Rhysida, Qilin, Akira have all hit EU targets). Hunt for Microsoft-signed PE binaries with certificate validity ≤72 hours issued by "Trusted Signing" intermediaries after 2025-05-01 where the signing CN does not match a known organisational EV entity. Where Teams.exe / AnyDesk.exe / PuTTY / Webex installers spawn `cmd.exe` / `powershell.exe` / `rundll32` / `regsvr32` without the expected Microsoft installer ancestry (Sysmon EID 1 with parent-image filter), treat as Oyster/Broomstick suspect. Restrict Artifact Signing tenant creation; require phishing-resistant MFA + compliant device for Azure subscription management; alert in Defender for Cloud Apps on rapid certificate creation from newly enrolled tenants (`Add-AzKeyVaultCertificate`).
