Top Highlights
- Microsoft revoked over 200 certificates used by the Vanilla Tempest threat actor to sign malicious binaries, enabling ransomware and backdoor deployment.
- These fake signatures were used in counterfeit Teams setup files to deliver the Oyster backdoor and Rhysida ransomware, often via SEO poisoning and malicious websites.
- Vanilla Tempest, active since 2022 and linked to various ransomware strains, used trusted signing services like DigiCert and GlobalSign to authenticate malicious content.
- Users are advised to download software only from verified sources and avoid clicking suspicious links to prevent infection via compromised search results and ads.
The Issue
In October 2025, Microsoft publicly revealed a significant cybersecurity disruption involving a threat actor they track as Vanilla Tempest, also known as Vice Society or Vice Spider. This group, active since late July 2022, specializes in deploying ransomware such as Rhysida, BlackCat, and Zeppelin, targeting organizations and individuals through sophisticated methods. Recently, Vanilla Tempest used maliciously signed fake Microsoft Teams setup files — counterfeit versions hosted on compromised websites that manipulate search engine results via SEO poisoning — to trick users into downloading harmful software. These fake installers, cleverly signed with trusted certificates obtained from reputable services like DigiCert and GlobalSign, maliciously delivered a backdoor called Oyster (also known as Broomstick), which then enabled the deployment of Rhysida ransomware, encrypting victim systems and demanding ransom payments. Microsoft’s Threat Intelligence team took swift action by revoking over 200 fraudulent certificates and updating security measures to flag these malicious signatures, aiming to prevent further infections. This incident underscores how cybercriminals exploit user trust in popular brand searches and the importance of downloading software solely from verified sources to avoid falling victim to such deceptions.
The detailed report was issued by Microsoft after uncovering the campaign in late September 2025 and confirming the activity earlier this month. It highlights the increasing sophistication of cybercriminal strategies—using fake trusted certificates and SEO poisoning techniques—to execute widespread ransomware operations. Security researchers and cybersecurity firms such as Blackpoint Cyber initially disclosed aspects of this activity, emphasizing the risks posed by malicious ads and search result manipulations that redirect users to dangerous download sites. The ongoing exploitation of legitimate trust and search engine vulnerabilities by Vanilla Tempest and similar groups illustrates the urgent need for enhanced vigilance and improved cybersecurity practices across the digital landscape.
Risk Summary
Cyber risks, exemplified by recent attacks involving threat actors like Vanilla Tempest, underscore the profound vulnerabilities in digital infrastructure, particularly through the exploitation of trusted digital certificates and deceptive online tactics. Malicious actors have leveraged fake software installers, such as impostor Microsoft Teams files, signed with legitimate certificates via trusted signing authorities, to clandestinely distribute backdoors like Oyster and deploying devastating ransomware like Rhysida. These campaigns, often propelled by SEO poisoning and malicious advertisements, prey on user trust and search engine vulnerabilities, enabling the malvertising of Trojanized applications on seemingly legitimate websites. The impact of such cyber risks is multifaceted, ranging from covert data breaches and system infiltrations to significant financial losses, operational disruptions, and erosion of trust in digital services. This escalating threat landscape necessitates rigorous verification of software sources, heightened awareness of search engine manipulation, and persistent updates to cybersecurity defenses to curtail the proliferation and impact of such sophisticated cyberattacks.
Possible Remediation Steps
Ensuring swift remediation in response to the revocation of fraudulent certificates during the Rhysida ransomware campaign is critical to protect systems from further exploitation and to maintain organizational trust and security integrity.
Mitigation and Remediation Steps
-
Immediate Revocation Verification: Confirm that affected certificates are promptly revoked and that revocation lists are up-to-date across all security tools.
-
Update Security Measures: Ensure all security solutions, such as firewalls, intrusion detection/prevention systems, and endpoint protections, recognize the revoked certificates to prevent malicious traffic.
-
Monitor Network Activity: Intensively monitor network activity for signs of phishing, impersonation, or malicious downloads attempting to exploit the compromised certificates.
-
Audit and Patch Systems: Conduct thorough system audits to identify vulnerabilities, and apply all necessary security patches to close potential entry points.
-
User Awareness Training: Educate employees on recognizing fraudulent communications and avoid opening suspicious links or attachments that could be linked to the malicious certificates.
-
Incident Response Readiness: Prepare and execute an incident response plan specifically tailored for ransomware threats, focusing on containment and recovery.
-
Collaboration with Authorities: Work closely with cybersecurity authorities and Microsoft’s security team to receive timely updates and guidance.
-
Secure Certificate Management: Review and strengthen certificate issuance, validation, and management policies to prevent future certification misuse.
-
Data Backup and Recovery: Maintain secure, offline backups of critical data to ensure rapid recovery if an infection occurs.
- Continuous Monitoring and Review: Keep ongoing surveillance of threat intelligence feeds and security alerts to detect evolving tactics associated with the campaign.
Advance Your Cyber Knowledge
Explore career growth and education via Careers & Learning, or dive into Compliance essentials.
Understand foundational security frameworks via NIST CSF on Wikipedia.
Disclaimer: The information provided may not always be accurate or up to date. Please do your own research, as the cybersecurity landscape evolves rapidly. Intended for secondary references purposes only.
Cyberattacks-V1
