Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

This top VC bets nearly 20% of its money on teenagers – here’s why

Too burnt out to travel? This new app will fake your summer vacation photos

Salesforce CEO Marc Benioff apologizes for saying San Francisco needs National Guard troops

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Microsoft revokes 200 fraudulent certificates used in Rhysida ransomware campaign
Identity

Microsoft revokes 200 fraudulent certificates used in Rhysida ransomware campaign

userBy userOctober 17, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

October 17, 2025Ravi LakshmananMalware/Cybercrime

Rhysida ransomware campaign

Microsoft on Thursday said it has revoked more than 200 certificates used by Vanilla Tempest, an attacker it tracks to fraudulently sign malicious binaries in ransomware attacks.

The Microsoft Threat Intelligence team said in a post shared on X that the certificate was “used in a fake Teams setup file to deliver the Oyster backdoor and ultimately deploy the Rhysida ransomware.”

The tech giant announced earlier this month that it had suspended the activity after it was detected in late September 2025. In addition to certificate revocation, the company’s security solutions have been updated to flag signatures associated with fake setup files, Oyster backdoor, and Rhysida ransomware.

Vanilla Tempest (formerly known as Storm-0832) is the name given to a financially motivated threat actor also known as Vice Society or Vice Spider, which is assessed to have been active since at least July 2022 and has distributed various ransomware strains over the years, including BlackCat, Quantum Locker, Zeppelin, and Rhysida.

DFIR retainer service

Oyster (also known as Broomstick and CleanUpLoader), on the other hand, is a backdoor that is often distributed via trojanized installers for popular software such as Google Chrome and Microsoft Teams using fake websites that users encounter when searching for programs on Google or Bing.

“In this campaign, Vanilla Tempest used a fake MSTeamsSetup.exe file hosted on a malicious domain that mimics Microsoft Teams. For example, teams-download[.]buzz, team install[.]Run or Team Download[.]Microsoft says, “Users can be directed to malicious download sites using search engine optimization (SEO) poisoning.”

To sign these installers and other post-compromise tools, the attackers allegedly used trusted signatures in addition to SSL.[.]com, DigiCert, and GlobalSign code signing services.

Details of the campaign were first revealed by Blackpoint Cyber ​​last month, showing how users searching for Teams online were redirected to a fake download page that served the malicious MSTeamsSetup.exe instead of the legitimate client.

CIS build kit

“This activity highlights the continued misuse of SEO poisoning and malicious advertising to deliver backdoors in products under the guise of trusted software,” the company said. “Those attackers are exploiting user trust in search results and well-known brands to gain initial access.”

To reduce such risks, we recommend that you only download software from verified sources and avoid clicking on suspicious links provided through search engine advertisements.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleOpenAI pauses Martin Luther King Jr.’s Sora video generation
Next Article Revolutionizing flexible perovskite solar cells
user
  • Website

Related Posts

New .NET CAPI backdoor targets Russian car and e-commerce companies via phishing ZIPs

October 18, 2025

Silver Fox spreads Winos 4.0 attack to Japan and Malaysia via HoldingHands RAT

October 18, 2025

Immortality is No Longer Science Fiction: TwinH’s AI Breakthrough Could Change Everything

October 17, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

This top VC bets nearly 20% of its money on teenagers – here’s why

Too burnt out to travel? This new app will fake your summer vacation photos

Salesforce CEO Marc Benioff apologizes for saying San Francisco needs National Guard troops

Salesforce CEO Marc Benioff apologizes for saying San Francisco needs National Guard troops

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Immortality is No Longer Science Fiction: TwinH’s AI Breakthrough Could Change Everything

The AI Revolution: Beyond Superintelligence – TwinH Leads the Charge in Personalized, Secure Digital Identities

Revolutionize Your Workflow: TwinH Automates Tasks Without Your Presence

FySelf’s TwinH Unlocks 6 Vertical Ecosystems: Your Smart Digital Double for Every Aspect of Life

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.