Fox TempestFox Tempest
Also known as: Fox Tempest
Known aliases
1
Profile
Fox Tempest is a financially motivated threat actor that operated a malware-signing-as-a-service (MSaaS) sold to other cybercriminals to sign malware, including ransomware, as trusted software and evade detection. The service, marketed through the domain signspace[.]cloud and a Telegram channel, abused Microsoft Artifact Signing to issue short-lived fraudulent code-signing certificates and offered signing plans priced between 5,000 and 9,000 USD, with higher tiers providing pre-configured virtual machines for signing malicious code. Microsoft tracked the operation from September 2025 and observed its certificates used to distribute malware families such as Oyster, Lumma Stealer, and Vidar and to support ransomware activity linked to Vanilla Tempest, Storm-0501, Storm-2561, and Storm-0249. In May 2026, Microsoft's Digital Crimes Unit disrupted the operation, seizing signspace[.]cloud, taking hundreds of signing virtual machines offline, and revoking more than 1,000 fraudulent certificates, and named Vanilla Tempest as a co-defendant in a case filed in the U.S. District Court for the Southern District of New York.
Aliases· 1
Fox Tempest