Switch language한국어
Back to the list

Microsoft revokes over 1,000 certificates that made malware look like “legitimate software”

TL;DR AI

Key summary

2 min read
  1. Microsoft said Fox Tempest ran a service that fraudulently obtained short-lived code-signing certificates to make malware look legitimate.

  2. The group abused Microsoft Artifact Signing to sign malware and impersonate trusted apps, including tools like AnyDesk, PuTTY, and Webex.

  3. Microsoft revoked more than 1,000 related certificates and said it disrupted the operation with help from Resecurity.

  4. The case shows how code-signing abuse helps malware evade detection and reflects a more service-based cybercrime model.

Read the original