Microsoft Dismantles Fox Tempest Malware-Signing Service Linked to Hospital Ransomware Attacks

Microsoft seized Fox Tempest's infrastructure in Operation OpFauxSign, dismantling a malware-signing-as-a-service platform that helped ransomware gangs disguise malware as legitimate software to attack hospitals, schools, and critical organisations worldwide.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region4 min read
Corporate cybersecurity incident response team reviewing malware alerts on operations centre screens following a major ransomware disruption

Corporate cybersecurity incident response team reviewing malware alerts on operations centre screens following a major ransomware disruption

Microsoft has seized the infrastructure of a cybercrime operation it calls Fox Tempest, dismantling a malware-signing-as-a-service platform that allowed ransomware gangs and other threat actors to disguise malicious software as legitimate applications and slip past enterprise security controls. The operation, codenamed OpFauxSign, was conducted in coordination with Resecurity, Europol's European Cybercrime Centre, and the FBI.

The platform had been active since May 2025. It abused Microsoft's Artifact Signing system to generate fraudulent code-signing certificates at scale, allowing customers to upload malware through an online portal and receive back a signed binary that appeared to be a legitimate, trusted application. Standard antivirus and endpoint detection tools, which rely in part on code signatures to assess trustworthiness, were significantly less likely to flag the resulting files.

The criminal model

Fox Tempest operated as a specialist service within the wider ransomware ecosystem. Rather than conducting attacks itself, it sold a critical enabler: the ability to make malware look legitimate. Customers paid thousands of dollars for this capability, reflecting the premium value of removing the detection friction that causes ransomware campaigns to fail. Microsoft described the service as representing a shift toward a modular cybercrime economy, where attacks are assembled from purchased services rather than executed end-to-end by a single group.

To build supply, Fox Tempest operators created hundreds of fraudulent Microsoft accounts using fabricated identities and impersonation of legitimate organisations, obtaining real code-signing credentials in volume. Malware delivered through the platform included Oyster, Lumma Stealer, and Vidar as information stealers, and ransomware strains including Rhysida, INC, Qilin, and Akira. The Vanilla Tempest ransomware group was named as a co-conspirator in a case Microsoft unsealed in the US District Court for the Southern District of New York.

Who was targeted

Organisations attacked through Fox Tempest-enabled campaigns included schools, hospitals, and other critical entities across multiple regions. Rhysida, one of the ransomware families linked to the service, was used in the attack on the British Library and in disruption of operations at Seattle-Tacoma International Airport. Microsoft also noted that illicit code-signing services of this type have been observed in attacks targeting critical infrastructure organisations in Europe, a pattern consistent with the broader use of signed malware to penetrate high-security environments.

For GCC enterprises, particularly those in healthcare, financial services, and government-adjacent sectors, the Fox Tempest case illustrates a direct operational risk: an attacker using a signed binary can bypass security controls that would otherwise flag the same payload. The implication for security teams is that code signature alone is not a sufficient trust signal, and that behavioural detection must be layered alongside signature-based controls.

The disruption and what comes next

Microsoft seized Fox Tempest's website at signspace[.]cloud, took offline hundreds of virtual machines running the operation, and blocked access to the site hosting the underlying code. As Microsoft applied pressure, Fox Tempest operators adapted in near real time: in February 2026 they shifted to networks of third-party-hosted virtual machines, and have since attempted to redirect customers to a separate code-signing service. Microsoft noted that cybercriminals have already been observed complaining in forums about access disruptions.

The case reinforces a pattern visible across recent Microsoft Digital Crimes Unit actions: sustained disruption of criminal infrastructure forces rebuilding costs, increases operational risk for attackers, and buys defenders meaningful time. Fox Tempest's rapid adaptation also illustrates why single takedowns rarely produce permanent resolution, and why GCC security operations teams must maintain continuous threat intelligence on the services cybercriminals rely on, not only on the malware families those services deliver.

The Fox Tempest operation generated millions in proceeds before dismantlement, demonstrating that the profitability of specialist cybercrime enablement services continues to attract sustained investment from organised criminal groups.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

Ransomware Intelligence GCCMicrosoft Threat IntelligenceCybercrime Ecosystem MENACritical Infrastructure SecurityEnterprise Threat Landscape 2026