Fox Tempest, also known as Forging Marauder, is a financially motivated cybercrime enabler that operated a malware-signing-as-a-service offering from at least May 2025. The group abused Microsoft Artifact Signing, formerly Azure Trusted Signing, to obtain short-lived code-signing certificates and sign customer-supplied malware, making malicious binaries appear to originate from trusted publishers and improving their ability to evade reputation- and signature-based defenses. Fox Tempest used hundreds of fraudulent Azure tenants and subscriptions and likely relied on stolen or fabricated identities, including identities associated with the United States and Canada, to pass signing-service verification. Its service was marketed through Telegram and online customer workflows, with customers able to submit malware and receive signed binaries; later operations used preconfigured third-party virtual machines to streamline signing. Fox Tempest-supported malware was commonly disguised as popular software including Microsoft Teams, AnyDesk, PuTTY, and Cisco Webex. Microsoft linked the service to Oyster, Lumma Stealer, Vidar, and ransomware activity involving Rhysida, INC, Qilin, Akira, and BlackByte, and identified customers or associated users including Vanilla Tempest, Storm-0501, Storm-0249, and Storm-2561. Microsoft disrupted the operation in May 2026 through legal action and infrastructure takedowns, including certificate revocation and removal of supporting virtual-machine infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware-signing-as-a-service operation that fraudulently obtained and created more than one thousand certificates, operated hundreds of Azure tenants and subscriptions, and signed customer-supplied malicious executables to make them appear trustworthy. It materially enabled Vanilla Tempest's Rhysida-related delivery activity.
Operated a malware-signing-as-a-service platform that generated code-signing certificates for malicious software used by multiple ransomware and malware operators.
A financially motivated Malware-Signing-as-a-Service operation that allegedly used compromised US and Canadian identities to obtain fraudulent Microsoft Trusted Signing certificates for ransomware and information-stealer operators. The report assesses the campaign's use of this signing tier as a medium-confidence sourcing correlation, not confirmed direct attribution.
Ran a malware-signing-as-a-service operation using fraudulently signed Microsoft Trusted Signing certificates to facilitate malware delivery with reduced detection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.