On October 17, 2025, Microsoft announced it had revoked over 200 digital certificates to disrupt a ransomware campaign that used fake Microsoft Teams installers. The threat actor, identified as Vanilla Tempest (also known as Vice Society), was distributing malware through these installers to deploy the Oyster backdoor and Rhysida ransomware. The fake installers and post-compromise tools were signed with certificates from various authorities, including Trusted Signing, SSL.com, DigiCert, and GlobalSign. By revoking these certificates, Microsoft has made it more difficult for the attackers to impersonate legitimate software and distribute their malicious payloads. This action is part of Microsoft's ongoing efforts to protect users from financially motivated cyber threats that involve ransomware and data exfiltration.
Microsoft Revokes Over 200 Certificates to Combat Ransomware Campaign Targeting Teams Users
MSFT
Related News
MSFT
Microsoft Launches Major AI Skilling Initiative for 2 Million Teachers in India
MSFT
Microsoft Trades Near $399 as Tech Sector Rallies on Economic Resilience
MSFT
OpenAI Nears Record $100B Funding at $850B Valuation to Fuel AI Infrastructure
MSFT
Microsoft Announces 240 New Marketplace Offers; Stock Up 1.06% Amid Broader Market Decline
MSFT