Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

What startups want from OpenAI

Why researchers are developing robots that look and act like bats

Data centers currently attract more investment than finding new sources of oil supply

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Microsoft revokes 200 fraudulent certificates used in Rhysida ransomware campaign
Identity

Microsoft revokes 200 fraudulent certificates used in Rhysida ransomware campaign

userBy userOctober 17, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

October 17, 2025Ravi LakshmananMalware/Cybercrime

Rhysida ransomware campaign

Microsoft on Thursday said it has revoked more than 200 certificates used by Vanilla Tempest, an attacker it tracks to fraudulently sign malicious binaries in ransomware attacks.

The Microsoft Threat Intelligence team said in a post shared on X that the certificate was “used in a fake Teams setup file to deliver the Oyster backdoor and ultimately deploy the Rhysida ransomware.”

The tech giant announced earlier this month that it had suspended the activity after it was detected in late September 2025. In addition to certificate revocation, the company’s security solutions have been updated to flag signatures associated with fake setup files, Oyster backdoor, and Rhysida ransomware.

Vanilla Tempest (formerly known as Storm-0832) is the name given to a financially motivated threat actor also known as Vice Society or Vice Spider, which is assessed to have been active since at least July 2022 and has distributed various ransomware strains over the years, including BlackCat, Quantum Locker, Zeppelin, and Rhysida.

DFIR retainer service

Oyster (also known as Broomstick and CleanUpLoader), on the other hand, is a backdoor that is often distributed via trojanized installers for popular software such as Google Chrome and Microsoft Teams using fake websites that users encounter when searching for programs on Google or Bing.

“In this campaign, Vanilla Tempest used a fake MSTeamsSetup.exe file hosted on a malicious domain that mimics Microsoft Teams. For example, teams-download[.]buzz, team install[.]Run or Team Download[.]Microsoft says, “Users can be directed to malicious download sites using search engine optimization (SEO) poisoning.”

To sign these installers and other post-compromise tools, the attackers allegedly used trusted signatures in addition to SSL.[.]com, DigiCert, and GlobalSign code signing services.

Details of the campaign were first revealed by Blackpoint Cyber ​​last month, showing how users searching for Teams online were redirected to a fake download page that served the malicious MSTeamsSetup.exe instead of the legitimate client.

CIS build kit

“This activity highlights the continued misuse of SEO poisoning and malicious advertising to deliver backdoors in products under the guise of trusted software,” the company said. “Those attackers are exploiting user trust in search results and well-known brands to gain initial access.”

To reduce such risks, we recommend that you only download software from verified sources and avoid clicking on suspicious links provided through search engine advertisements.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleOpenAI pauses Martin Luther King Jr.’s Sora video generation
Next Article Revolutionizing flexible perovskite solar cells
user
  • Website

Related Posts

Google sues China-based hackers behind $1 billion Lighthouse phishing platform

November 12, 2025

Amazon discovers zero-day flaw in attacks exploiting Cisco ISE and Citrix NetScaler

November 12, 2025

[Webinar] See how leading security teams use DASR to reduce attack surface exposure

November 12, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

What startups want from OpenAI

Why researchers are developing robots that look and act like bats

Data centers currently attract more investment than finding new sources of oil supply

Lawmakers warn Democratic governors that states are sharing driver data with ICE

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Meet Your Digital Twin: Europe’s Cutting-Edge AI is Personalizing Medicine

TwinH: The AI Game-Changer for Faster, More Accessible Legal Services

Immortality is No Longer Science Fiction: TwinH’s AI Breakthrough Could Change Everything

The AI Revolution: Beyond Superintelligence – TwinH Leads the Charge in Personalized, Secure Digital Identities

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.