Microsoft revokes over 1,000 certificates that made malware look like “legitimate software”

TL;DR AI
2 min readKey summary
Microsoft said Fox Tempest ran a service that fraudulently obtained short-lived code-signing certificates to make malware look legitimate.
The group abused Microsoft Artifact Signing to sign malware and impersonate trusted apps, including tools like AnyDesk, PuTTY, and Webex.
Microsoft revoked more than 1,000 related certificates and said it disrupted the operation with help from Resecurity.
The case shows how code-signing abuse helps malware evade detection and reflects a more service-based cybercrime model.



