Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Microsoft Halts Vanilla Tempest Cyberattack by Revoking Malicious Teams Installer Certificates

Microsoft has effectively disrupted a significant cyberattack campaign orchestrated by the Vanilla Tempest threat group in early October 2025. The company revoked over 200 fraudulent certificates that were used by cybercriminals to sign counterfeit…

Microsoft has effectively disrupted a significant cyberattack campaign orchestrated by the Vanilla Tempest threat group in early October 2025. The company revoked over 200 fraudulent certificates that were used by cybercriminals to sign counterfeit Microsoft Teams installation files. These files were designed to deliver the Oyster backdoor and deploy Rhysida ransomware on victim systems.

Microsoft security researchers identified this Vanilla Tempest campaign in late September 2025 after observing several months of suspicious activity involving fraudulently signed binary files. The company responded swiftly by revoking the malicious certificates and ensuring that Microsoft Defender Antivirus can detect the fake setup files, Oyster backdoor, and Rhysida ransomware.

Furthermore, Microsoft Defender for Endpoint now recognizes the specific tactics, techniques, and procedures used by Vanilla Tempest in their attacks. Vanilla Tempest is a financially motivated cybercriminal group, also known by other security vendors as VICE SPIDER and Vice Society. The group specializes in deploying ransomware and stealing sensitive data for extortion purposes.

Throughout their operation history, Vanilla Tempest has utilized multiple ransomware variants, including BlackCat, Quantum Locker, and Zeppelin, with a recent focus on deploying Rhysida ransomware. The attack campaign relied on sophisticated social engineering techniques to deceive users into downloading malicious software.

Microsoft has effectively disrupted a significant cyberattack campaign orchestrated by the Vanilla Tempest threat group in early October 2025.
Anthony Reid · Thehackingpost

Vanilla Tempest created fake MSTeamsSetup.exe files and hosted them on deceptive domains that closely mimicked legitimate Microsoft Teams websites, such as teams-download[.]buzz, teams-install[.]run, and teams-download[.]top. Security researchers suggest that potential victims were led to these malicious download sites through search engine optimization poisoning, a method that manipulates search engine results to prominently display malicious links.

Upon executing the fake Microsoft Teams setup files, the malware delivered a loader that subsequently installed a fraudulently signed Oyster backdoor on their systems. Investigations revealed that Vanilla Tempest began incorporating Oyster into their attack campaigns as early as June 2025, but only started fraudulently signing these backdoors in early September 2025.

To make their malicious software appear legitimate, Vanilla Tempest exploited multiple trusted code signing services. The threat actors used Microsoft’s Trusted Signing service, along with certificates from SSL[.]com, DigiCert, and GlobalSign to fraudulently sign both fake installers and post-compromise tools.

Advertisement

Microsoft highlighted that fully enabled Microsoft Defender Antivirus successfully blocks this threat. The company has also provided additional guidance through Microsoft Defender for Endpoint to assist organizations in mitigating and investigating this attack. By releasing this threat intelligence publicly, Microsoft aims to enhance cybersecurity defenses across the broader security community.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories