Microsoft Halts Vanilla Tempest Cyberattack by Revoking Malicious Teams Installer Certificates
Microsoft has effectively disrupted a significant cyberattack campaign orchestrated by the Vanilla Tempest threat group in early October 2025. The company revoked over 200 fraudulent certificates that were used by cybercriminals to sign counterfeit…
Microsoft has effectively disrupted a significant cyberattack campaign orchestrated by the Vanilla Tempest threat group in early October 2025. The company revoked over 200 fraudulent certificates that were used by cybercriminals to sign counterfeit Microsoft Teams installation files. These files were designed to deliver the Oyster backdoor and deploy Rhysida ransomware on victim systems.
Microsoft security researchers identified this Vanilla Tempest campaign in late September 2025 after observing several months of suspicious activity involving fraudulently signed binary files. The company responded swiftly by revoking the malicious certificates and ensuring that Microsoft Defender Antivirus can detect the fake setup files, Oyster backdoor, and Rhysida ransomware.
Furthermore, Microsoft Defender for Endpoint now recognizes the specific tactics, techniques, and procedures used by Vanilla Tempest in their attacks. Vanilla Tempest is a financially motivated cybercriminal group, also known by other security vendors as VICE SPIDER and Vice Society. The group specializes in deploying ransomware and stealing sensitive data for extortion purposes.
Throughout their operation history, Vanilla Tempest has utilized multiple ransomware variants, including BlackCat, Quantum Locker, and Zeppelin, with a recent focus on deploying Rhysida ransomware. The attack campaign relied on sophisticated social engineering techniques to deceive users into downloading malicious software.
Microsoft has effectively disrupted a significant cyberattack campaign orchestrated by the Vanilla Tempest threat group in early October 2025.
Vanilla Tempest created fake MSTeamsSetup.exe files and hosted them on deceptive domains that closely mimicked legitimate Microsoft Teams websites, such as teams-download[.]buzz, teams-install[.]run, and teams-download[.]top. Security researchers suggest that potential victims were led to these malicious download sites through search engine optimization poisoning, a method that manipulates search engine results to prominently display malicious links.
Upon executing the fake Microsoft Teams setup files, the malware delivered a loader that subsequently installed a fraudulently signed Oyster backdoor on their systems. Investigations revealed that Vanilla Tempest began incorporating Oyster into their attack campaigns as early as June 2025, but only started fraudulently signing these backdoors in early September 2025.
To make their malicious software appear legitimate, Vanilla Tempest exploited multiple trusted code signing services. The threat actors used Microsoft’s Trusted Signing service, along with certificates from SSL[.]com, DigiCert, and GlobalSign to fraudulently sign both fake installers and post-compromise tools.
Microsoft highlighted that fully enabled Microsoft Defender Antivirus successfully blocks this threat. The company has also provided additional guidance through Microsoft Defender for Endpoint to assist organizations in mitigating and investigating this attack. By releasing this threat intelligence publicly, Microsoft aims to enhance cybersecurity defenses across the broader security community.
Based on reporting by GBHackers.
