HomeSecurityMicrosoft discontinues malware code-signing service

Microsoft discontinues malware code-signing service

Microsoft has shut down the infrastructure that supported the largest malware code-signing service, which was used to help ransomware groups and other cybercriminals make malware harder to detect on Windows. The threat actors behind the service used stolen identities and impersonated legitimate organizations to obtain more than 1,000 code-signing certificates.

Microsoft malware code-signing

Microsoft seized the group’s website, signspace[.]cloud, revoked the abusive certificates, which were obtained through the Artifact Signing, and took down hundreds of virtual machines created by the attackers on Azure. Cybercriminals were paying between $5,000 and $9,000 to use the “malware signing as a service” (MSaaS) service, underscoring its importance and effectiveness.

See also: INTERPOL: Operation Ramz disrupts cybercrime networks

Microsoft researchers have identified clear connections between the group running this operation (Fox Tempest) and ransomware collaborators who worked with gangs such as INC, Qilin, Akira, and Rhysida.

A ransomware group tracked as Vanilla Tempest used the code-signing service to create malicious installers for enterprise software, including AnyDesk, Microsoft Teams, Putty, and Webex. These fake but digitally signed installers were distributed via SEO poisoning and malvertising  and were used to deploy a variety of backdoors, infostealers, and ransomware programs.

“This case shows how cybercrime is changing,” said Steven Masada, assistant general counsel for Microsoft’s Digital Crimes Unit. “Whereas it once required a single team to execute an attack from start to finish, we now have a modular ecosystem where services are bought and sold and operate interchangeably with each other. Some services are cheap and widely used. Others, like Fox Tempest’s, are highly specialized and expensive because they remove friction or bypass obstacles that make attacks fail, making them more reliable and harder to detect.”

Why this malware code-signing service is important

The value of digitally signing executable files is that Microsoft Defender SmartScreen will display weaker warnings for downloaded files , or even no warning at all, if the file has developed a clean reputation over time. For attacks based on running malicious installers that pretend to be popular applications, the absence of scary warnings is a big advantage.

See also: Microsoft reveals Storm-2949 attack on Azure Cloud and Microsoft 365

Microsoft discontinues malware code-signing service

For a digital signature to be valid, it must be created from a code signing certificate issued by one of the trusted Certificate Authorities in the Windows Trust Store. Microsoft offers such a service under Azure called Artifact Signing through which developers can obtain short-lived certificates for their applications, but this process requires identity verification.

Fox Tempest likely used stolen identities to bypass the verification process and created hundreds of Azure accounts and tenants for use by its business. The group then built its service on top of these subscriptions and provided code signing services to the cybercrime ecosystem since at least May 2025.

“Illegal certificates have been sold and traded for more than a decade,” Masada said. “This includes their use by government agencies to target critical infrastructure organizations in Europe. What has changed is how this activity is marketed, packaged, and sold as a service, along with the scale at which it is now used in ransomware campaigns. Instead of buying certificates one by one, criminals upload their malware to a service that signs it for them.”

Microsoft’s takedown of Fox Tempest’s infrastructure is a clear example of cybercrime’s transition to a fully organized and commercialized operating model. Modern ransomware attacks are no longer based solely on the capabilities of a single hacker group, but on a vast underground ecosystem of services operating on “cybercrime-as-a-service”. From selling stolen credentials to providing malware signing services and ready-made cloud infrastructure, attackers can now purchase almost any tool needed for a successful breach. The ability to digitally sign malicious files is considered particularly critical, as it allows malware to appear as trusted software, bypassing security mechanisms and reducing warnings to victims.

See also: ChromaDB: Critical vulnerability allows pre-auth RCE via HuggingFace

Microsoft discontinues malware code-signing service

At the same time, the case highlights the enormous challenges that cloud providers and technology giants face in their efforts to limit the abuse of their services. The use of stolen identities to issue code-signing certificates and the creation of hundreds of Azure tenants show that cybercriminals are now investing in infrastructure with professional characteristics and a high level of organization. Experts estimate that the fight against supply chain attacks and malware signing services will be one of the biggest challenges of the next decade, as trust in the digital ecosystem now depends not only on the security of the software, but also on the reliability of its certification and distribution mechanisms themselves.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS