Fox Tempest
Fox Tempest, also referred to as Forging Marauder, is a financially motivated threat actor operating a malware-signing-as-a-service (MSaaS) offering used by other cybercriminals. Active since at least May 2025, the group abused Microsoft Artifact Signing (formerly Trusted Signing / Azure Artifact Signing) to generate short-lived fraudulent code-signing certificates, allowing malicious binaries to appear legitimate and evade security controls. Microsoft reported that Fox Tempest created more than 1,000 fraudulent certificates and hundreds of Azure tenants and subscriptions, and operated infrastructure including signspace[.]cloud and later pre-configured third-party virtual machines to let customers upload malware and receive signed binaries. Fox Tempest functioned primarily as an upstream enabler in the malware and ransomware ecosystem rather than as a direct intrusion actor. Reporting links its signing service to malware and ransomware activity involving Oyster, Lumma Stealer, Vidar, Rhysida, Akira, INC, Qilin, and BlackByte, and to customer or associated actors including Vanilla Tempest, Storm-0501, Storm-2561, and Storm-0249. Microsoft also named Vanilla Tempest as a co-conspirator in legal action tied to the disruption. Signed malware was disguised as legitimate software such as Microsoft Teams, AnyDesk, PuTTY, and Webex, and was distributed through techniques including malvertising, SEO poisoning, fake download pages, and other social engineering lures. Microsoft and partners disrupted Fox Tempest in May 2026 by seizing signspace[.]cloud, taking offline hundreds of virtual machines, blocking access to supporting infrastructure, and revoking more than 1,000 code-signing certificates. Reporting also states the service was advertised through Telegram, charged thousands of dollars in Bitcoin, and generated millions of dollars in revenue.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
5 malware families attributed to this actor across reporting.
Observables
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ran a malware-signing-as-a-service operation using fraudulently signed Microsoft Trusted Signing certificates to facilitate malware delivery with reduced detection.
Malware-signing-as-a-service provider whose infrastructure supplied fraudulently obtained Microsoft Trusted Signing certificates used to sign malicious installers.
Operates a malware-signing service that provides fraudulent code-signing for malware used by multiple criminal actors.
Financially motivated threat actor operating a malware-signing-as-a-service offering used by other threat actors to sign malware and improve trust and evasion.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.