Resecurity Supports Microsoft DCU in Disrupting Fox Tempest ’s Cybercriminal Code-Signing Ecosystem


Resecurity Supports Microsoft DCU in Disrupting Fox Tempest ’s Cybercriminal Code-Signing Ecosystem

Pierluigi Paganini
May 28, 2026

Microsoft and Resecurity disrupted Fox Tempest, a malware-signing service that used fake Microsoft certificates to make malware look legitimate.

Resecurity supported Microsoft’s Digital Crimes Unit (DCU) in its disruption of Fox Tempest, a financially motivated threat actor operating a malware-signing-as-a-service (MSaaS) capability used by cybercriminals to make malicious files appear legitimate.

On May 19, 2026, Microsoft unsealed a legal case in the U.S. District Court for the Southern District of New York targeting Fox Tempest, a cybercrime service that abused Microsoft Artifact Signing to obtain fraudulent code-signing certificates. According to Microsoft, the service enabled cybercriminals to disguise malware as trusted software, improving the likelihood that malicious files would bypass security controls and be executed by victims.

As part of the disruption, Microsoft seized the malware-signing service website signspace[.]cloud, took offline hundreds of virtual machines used in the operation, blocked access to infrastructure hosting the underlying code, and revoked more than 1,000 code-signing certificates attributed to Fox Tempest.

Fox Tempest played an upstream role in the ransomware ecosystem. Rather than directly targeting victims, the group provided a specialized service that enabled other threat actors to digitally sign malware, improve the effectiveness of malicious distribution campaigns, and increase the perceived legitimacy of malicious software. Microsoft linked Fox Tempest-enabled activity to ransomware and malware operations involving Vanilla Tempest, Rhysida, Oyster, Lumma Stealer, Vidar, INC, Qilin, Akira, and other families or affiliates.

Resecurity collaborated with Microsoft DCU to help better understand how Fox Tempest operated. Microsoft also noted coordination with Europol’s European Cybercrime Centre (EC3) and the Federal Bureau of Investigation (FBI), underscoring the importance of public-private collaboration in disrupting cybercrime infrastructure.

The case highlights a broader shift in cybercrime: attackers increasingly rely on modular, commercialized services that remove friction from the attack chain. By weaponizing code signing, Fox Tempest helped make malicious software look trusted, reducing user suspicion and increasing the chances of successful compromise.

Disrupting these services upstream is critical. When malicious code-signing ecosystems are degraded, ransomware operators and malware distributors lose a key capability, attacks become harder to scale, and defenders gain more opportunity to stop threats before they reach victims.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Code-Signing Ecosystem)







Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


Samsung is facing a fresh legal challenge that could put a big red “Stop” sign for its foldable phones in the US. Lepton Computing LLC has just filed a lawsuit in a Texas federal court, accusing the South Korean tech giant and its US arm of infringing multiple patents related to foldable phone technology.

If the legal action escalates, it could impact sales of Samsung’s Galaxy Z lineup, which includes the Fold, Flip, and new TriFold models.

What the lawsuit claims

In the legal filing, which was later covered by The Biz, Lepton alleges that Samsung is using patented technologies for flexible display structure, hinge mechanism, and user interface behaviors without authorization. The company claims that it developed these ideas years prior to these foldable phones hitting the market.

The patents in question include concepts around how foldable displays operate and how software adapts to the changing screen states. Both of these are practically central to modern foldable devices. Now, Lepton is seeking damages. But what’s more notable is that it’s pushing for a potential ban on Samsung’s foldable phones in the US market.

What’s the verdict?

Keep in mind that claiming patent infringement is not the same as actually proving it. Patent disputes in the tech industry are often complex due to overlapping ideas, prior art, and competing claims. While Lepton does hold patents related to foldable technology, this doesn’t immediately prove that Samsung has violated them.

Samsung already has an extensive portfolio of patents around foldable tech that it has built over years of research and development, which will likely play a central role if the case does end up moving forward.

Why does this matter, and what happens next?

Samsung is one of the largest brands in the foldable phone market, especially in the US, where the only real competition is Motorola’s Razr series. So any disruption could have notable effects across the entire segment. In the extreme scenario that Samsung does get barred from selling foldables in the US, Apple’s upcoming foldable iPhone could enter the market with virtually no competition.

At the moment, this is still in the early stages of a legal battle. Cases like this can often take years to resolve, with the outcomes usually involving a hefty settlement. Till then, it remains a developing story.



Source link