Microsoft Squashes Vanilla Tempest: 200+ Fake Teams Certificates Revoked!
Microsoft just pulled the plug on over 200 certificates used by Vanilla Tempest to sign fake Teams installers. The cybercriminals were spreading the Oyster backdoor and Rhysida ransomware like they were handing out free samples at a trade show.

Hot Take:
It seems Vanilla Tempest thought they could outwit Microsoft by sneaking in fake Teams installers, but it turns out their stormy tactics were more of a drizzle. Kudos to Microsoft for revoking those certificates before Vanilla Tempest could rain on anyone else’s parade!
Key Points:
- Microsoft revoked over 200 certificates used by Vanilla Tempest for fake Teams installers.
- The group targeted various sectors using multiple ransomware payloads.
- Vanilla Tempest distributed fake installers through SEO poisoning and fraudulent domains.
- Microsoft ensured Defender Antivirus can detect these threats with added indicators of compromise.
- The campaign was disrupted in early October 2025, neutralizing the threat.
Already a member? Log in here
