INTEL_REPORT
Microsoft Security Blog · published 5/19/2026, 3:07:01 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Exposing Fox Tempest: A malware-signing service operation Fox Tempest is a financially motivated threat actor operating a malware‑signing‑as‑a‑service (MSaaS) used by other cybercriminals, including Vanilla Tempest and Storm groups, to more effectively distribute malicious code, including ransomware. The post Exposing Fox Tempest: A malware-signing service operation appeared first on Microsoft Security Blog . In this article Fox Tempest’s role and impact Fox Tempest’s malwa…
https://www.microsoft.com/en-us/security/blog/2026/05/19/exposing-fox-tempest-a-malware-signing-service-operation
sha256:f18b190de8fedf24951622bd6d0b75ee414d0c57a0c78288cf1616b7badd4fd9
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| f0668ce925f36ff7f3359b0ea47e3fa243af13cd6ad9661dfccc9ff79fb4f1cc |
| Open → |
| sha256 | 11af4566539ad3224e968194c7a9ad7b596460d8f6e423fc62d1ea5fc0724326 | Open → |
| sha256 | f0a6b89ec7eee83274cd484cea526b970a3ef28038799b0a5774bb33c5793b55 | Open → |