UnknownUnknown

Fox Tempest

Financially motivated threat actor tracked under the Microsoft Tempest naming convention.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
6.8
Moderate signal strength
Mentions10
Sources4
High conf.8
Last seenMay 2026
First observed
Last active
Origin
Aliases
1
Techniques
0
Campaigns
0

Attribution signals

10 mentions · 4 sources
#1attributedhigh
Infrastructure
mstic
May 2026

"Microsoft has revoked over one thousand code signing certificates attributed to Fox Tempest."

#2assesseshigh
Unspecified
mstic
May 2026

"Microsoft Threat Intelligence assesses that Fox Tempest is a well-resourced group handling infrastructure creation, customer r"

#3linkedhigh
InfrastructureMalware
mstic
May 2026

"Microsoft Threat Intelligence has linked the actor to various ransomware groups including Vanilla Tempest, Storm-0501, Storm-2561, and Storm-0249, who have all leveraged Fox Tempest-signed malware in active intrusions."

#4high
Infrastructure
security-affairs
May 2026
#5linkedhigh
InfrastructureMalware
security-affairs
May 2026

"Microsoft linked Fox Tempest-enabled activity to ransomware and malware operations involving Vanilla Tempest, Rhysida, Oyster, Lumma Stealer, Vidar, INC, Qilin, Akira, and other families or affiliates."

#6linkedhigh
InfrastructureMalwareTTP match
mstic
May 2026

"Microsoft Threat Intelligence has tracked Fox Tempest since September 2025. Microsoft Threat Intelligence has linked the actor to various ransomware groups including Vanilla Tempest, Storm-0501, Storm-2561, and Storm-0249, who have all leveraged Fox Tempest-signed malware in active intrusions."

#7assesseshigh
Infrastructure
mstic
May 2026

"Microsoft Threat Intelligence assesses that Fox Tempest is a well-resourced group handling infrastructure creation"

#8trackedhigh
Unspecified
mstic
May 2026

"Microsoft Threat Intelligence has tracked Fox Tempest since September 2025."

#9unspecified
Infrastructure
habr
May 2026
#10unspecified
InfrastructureMalware
cyberscoop
May 2026

Hedge terms observed

assessesattributedlinkedtracked