Microsoft Disrupts Malware-Signing Service Used in Ransomware Attacks

Fox Tempest threat actor exploited Microsoft’s Artifact Signing system to deliver signed malware to thousands of compromised systems globally.

Illustration: Microsoft Disrupts Malware-Signing Service Used in Ransomware Attacks

Fox Tempest threat actor exploited Microsoft’s Artifact Signing system to deliver signed malware to thousands of compromised systems globally.

  • Microsoft shut down a malware-signing-as-a-service operation run by Fox Tempest threat actor
  • The scheme weaponised Microsoft’s Artifact Signing system to deliver legitimate-appearing malicious code
  • Thousands of machines and networks were compromised through ransomware and other attacks using signed malware

Microsoft has disrupted a malware-signing-as-a-service operation that exploited the company’s own Artifact Signing system to distribute malicious code and conduct ransomware attacks across thousands of compromised systems worldwide.

The tech giant attributed the activity to a threat actor it calls Fox Tempest, which offered the malware-signing service to other cybercriminals. The scheme leveraged Microsoft’s legitimate code-signing infrastructure to make malicious software appear trustworthy to security systems and users.

Code signing is a critical security mechanism that allows software publishers to digitally sign their applications, providing assurance to users and security systems that the code is authentic and has not been tampered with. By compromising this process, Fox Tempest was able to distribute malware that bypassed many traditional security controls.

The disruption represents a significant blow to a sophisticated cybercriminal operation that had been providing signing services to multiple threat actors. This type of malware-signing-as-a-service model allows less technically sophisticated criminals to access advanced evasion techniques previously available only to elite threat groups.

Microsoft’s Artifact Signing system, part of the company’s broader security infrastructure, was weaponised to provide digital certificates that made malicious code appear legitimate. This allowed the signed malware to evade detection by security software that relies on code-signing verification as a trust indicator.

The global scope of the operation indicates Fox Tempest had developed a scalable infrastructure for distributing signed malware to customers conducting various types of cyberattacks, including ransomware campaigns. The use of legitimate signing infrastructure represents an evolution in threat actor tactics to bypass security controls.

Why It Matters

This incident highlights a critical vulnerability in the trust model that underpins modern cybersecurity defences. When threat actors compromise legitimate code-signing infrastructure, they can effectively bypass security controls that rely on digital signatures as trust indicators. CISOs need to reassess their organisation’s reliance on code-signing verification as a primary security control and implement additional layers of protection.

The malware-signing-as-a-service model also represents a concerning trend towards commoditised advanced attack techniques. This democratisation of sophisticated evasion methods means organisations may face more frequent attacks using previously elite tactics, requiring enhanced detection capabilities and security awareness programs.

What To Do Now

  • Review your organisation’s security policies regarding code-signing verification and implement additional validation mechanisms beyond digital signatures
  • Assess whether your security tools have adequate behavioural analysis capabilities to detect malware even when it appears legitimately signed
  • Monitor Microsoft’s security advisories for additional technical details and indicators of compromise related to this campaign

Sources