Fox Tempest, also known as Forging Marauder, is a financially motivated cybercrime enabler that operates a malware-signing-as-a-service offering for other threat actors. Active since at least May 2025, the group abused Microsoft Artifact Signing to obtain large volumes of short-lived fraudulent code-signing certificates and used them to make malicious binaries appear legitimate and more likely to evade security controls. The operation functioned as an upstream service in the malware and ransomware ecosystem rather than primarily conducting victim intrusions directly. Fox Tempest provided customers with a portal and later preconfigured virtual-machine-based workflows that allowed malicious files to be uploaded and returned as digitally signed binaries. The group created hundreds of cloud tenants and subscriptions and generated more than 1,000 fraudulent certificates at scale. Reporting links the service to malware and ransomware activity involving Oyster, Lumma Stealer, Vidar, Rhysida, Akira, INC, Qilin, and BlackByte, and to customer or associated actors including Vanilla Tempest, Storm-0501, Storm-0249, Storm-2561, and Storm-3075. Signed malware was commonly disguised as legitimate software installers or utilities to increase user trust and reduce early detection. The actor’s role centered on defense evasion and malware distribution enablement. Fox Tempest’s signed malware was used in campaigns delivered through malvertising, SEO poisoning, fake software download pages, and other social-engineering-driven distribution channels. The service materially supported ransomware deployment and infostealer delivery by improving execution success and bypassing reputation-based controls. Microsoft assessed the operation as sophisticated and well resourced, with dedicated functions for infrastructure management, customer relations, and financial transactions, and reported that the service generated millions of dollars in revenue. Fox Tempest is also assessed to have relied on stolen or fabricated identities, including identities associated with the United States and Canada, to satisfy verification requirements for certificate issuance. In May 2026, Microsoft and partners disrupted the operation by revoking more than 1,000 certificates, seizing infrastructure, disabling supporting virtual machines and accounts, and pursuing legal action. The disruption forced downstream actors that had relied on Fox Tempest’s signing capability to change delivery methods.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operated a malware-signing-as-a-service platform that generated code-signing certificates for malicious software used by multiple ransomware and malware operators.
Ran a malware-signing-as-a-service operation using fraudulently signed Microsoft Trusted Signing certificates to facilitate malware delivery with reduced detection.
Malware-signing-as-a-service provider whose infrastructure supplied fraudulently obtained Microsoft Trusted Signing certificates used to sign malicious installers.
Operates a malware-signing service that provides fraudulent code-signing for malware used by multiple criminal actors.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.