Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Ransomware

Microsoft Revokes Over 200 Certificates to Disrupt Ransomware Campaign

The tech giant attributed the attacks to Vanilla Tempest, also known as Vice Spider and Vice Society.

Ransomware

Microsoft announced on Wednesday that it has disrupted a Vanilla Tempest campaign whose goal was the deployment of Rhysida ransomware.

Vanilla Tempest, also known as Vice Spider and Vice Society, has been around since at least 2021, mainly known for its ransomware attacks on the education and healthcare sectors. 

Vice Society had its own leak website until 2023, disappearing at around the time when the notorious Rhysida ransomware emerged. The threat group has been known to deploy various file encryptors in its attacks, including BlackCat, Quantum Locker, and Zeppelin, but recently it has mainly used Rhysida ransomware.

Microsoft said it disrupted a Vanilla Tempest campaign in early October by revoking more than 200 certificates used by the cybercriminals to sign their malware.

According to the tech giant, the hackers signed fake Microsoft Teams setup files designed to install a backdoor named Oyster, which in turn would enable them to deploy Rhysida ransomware.

The fake Teams installers were delivered through websites hosted on domains such as ‘teams-download.buzz’ and ‘teams-install.run’. Victims were likely lured to these sites through SEO poisoning. 

Advertisement. Scroll to continue reading.

When victims ran the fake Teams setup files, they executed a loader that downloaded a signed version of the Oyster backdoor, which has been used by Vanilla Tempest since at least June 2025. The cybercriminals started signing the backdoor in early September.

“To fraudulently sign the fake installers and post-compromise tools, Vanilla Tempest was observed using Trusted Signing, as well as SSL[.]com, DigiCert, and GlobalSign code signing services,” Microsoft said.

Microsoft’s actions make the malware distributed by Vanilla Tempest easier to detect and block, and the immediate impact on the cybercrime operation may be significant, but the threat actors will likely re-arm with new certificates and slightly modified tactics.

Related: RaccoonO365 Phishing Service Disrupted, Leader Identified

Related: RapperBot Botnet Disrupted, American Administrator Indicted

Related: Recently Disrupted DanaBot Leaked Valuable Data for 3 Years

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.