Microsoft's Digital Crimes Unit disrupted a malware-signing-as-a-service (MSaaS) operation called Fox Tempest that abused the Azure Artifact Signing platform to generate fraudulent code-signing certificates. The threat actor created over 1,000 certificates and hundreds of Azure tenants, using stolen identities and short-lived 72-hour certificates to evade detection. Signed malware was used in campaigns involving Lumma Stealer, Oyster, Rhysida, Akira, and other ransomware families. Microsoft seized the signspace[.]cloud domain, took hundreds of VMs offline, and filed a legal case in the Southern District of New York. The service was sold on Telegram for $5,000–$9,000 in bitcoin and generated millions in profits.

4m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Related Articles:
4 Impressions