Microsoft Revokes Over 200 Certificates to Disrupt Ransomware Campaign
securityweek
Microsoft announced on Wednesday that it has disrupted a Vanilla Tempest campaign whose goal was the deployment of Rhysida ransomware.
Vanilla Tempest, also known as Vice Spider and Vice Society, has been around since at least 2021, mainly known for its ransomware attacks on the education and healthcare sectors.
Vice Society had its own leak website until 2023, disappearing at around the time when the notorious Rhysida ransomware emerged. The threat group has been known to deploy various file encryptors in its attacks, including BlackCat, Quantum Locker, and Zeppelin, but recently it has mainly used Rhysida ransomware.
Microsoft said it disrupted a Vanilla Tempest campaign in early October by revoking more than 200 certificates used by the cybercriminals to sign their malware.
According to the tech giant, the hackers signed fake Microsoft Teams setup files designed to install a backdoor named Oyster, which in turn would enable them to deploy ...
Copyright of this story solely belongs to securityweek . To see the full text click HERE