Risky Bulletin Newsletter
May 20, 2026
Risky Bulletin: Microsoft takes down MSaaS used by ransomware gangs
Presented by
News Editor
Microsoft has sued and seized domains and server infrastructure belonging to SignSpaceCloud (signspace[.]cloud), a Russian cybercrime service that sold code signing certificates to malware and ransomware gangs.
The service, which Microsoft is tracking as Fox Tempest, has been running since May of last year and is what cybersecurity experts call a malware-signing-as-a-service (MSaaS).
The group used hundreds of fake accounts on the Microsoft Artifact Signing service to obtain code signing certificates that it later resold on its website for thousands of US dollars.