SYMBOLCOMMON_NAMEaka. SYNONYMS

Fox Tempest  (Back to overview)


Fox Tempest is a financially motivated threat actor that operated a malware-signing-as-a-service (MSaaS) sold to other cybercriminals to sign malware, including ransomware, as trusted software and evade detection. The service, marketed through the domain signspace[.]cloud and a Telegram channel, abused Microsoft Artifact Signing to issue short-lived fraudulent code-signing certificates and offered signing plans priced between 5,000 and 9,000 USD, with higher tiers providing pre-configured virtual machines for signing malicious code. Microsoft tracked the operation from September 2025 and observed its certificates used to distribute malware families such as Oyster, Lumma Stealer, and Vidar and to support ransomware activity linked to Vanilla Tempest, Storm-0501, Storm-2561, and Storm-0249. In May 2026, Microsoft's Digital Crimes Unit disrupted the operation, seizing signspace[.]cloud, taking hundreds of signing virtual machines offline, and revoking more than 1,000 fraudulent certificates, and named Vanilla Tempest as a co-defendant in a case filed in the U.S. District Court for the Southern District of New York.


Associated Families

There are currently no families associated with this actor.


References
2026-05-19MicrosoftSteven Masada
Disrupting Fox Tempest: A cybercrime service that turned “verified” software into a pathway for ransomware
Akira INC Qilin Rhysida AgendaCrypt Akira Broomstick INC Lumma Stealer Rhysida Vidar Fox Tempest
2026-05-19The RecordJonathan Greig
Microsoft disrupts Fox Tempest malware-signing-as-a-service platform tied to ransomware gangs
Akira INC Qilin Rhysida AgendaCrypt Akira Broomstick INC Lumma Stealer Rhysida Vidar Fox Tempest
2026-05-19MicrosoftMicrosoft Threat Intelligence
Exposing Fox Tempest: A malware-signing service operation (Podcast)
Akira Rhysida Akira BlackByte BlueSky Broomstick Lumma Stealer Rhysida Spyder Vidar Fox Tempest

Credits: MISP Project