Microsoft Squashes Vanilla Tempest: 200+ Fake Teams Certificates Revoked!

Microsoft just pulled the plug on over 200 certificates used by Vanilla Tempest to sign fake Teams installers. The cybercriminals were spreading the Oyster backdoor and Rhysida ransomware like they were handing out free samples at a trade show.

Pro Dashboard

Hot Take:

It seems Vanilla Tempest thought they could outwit Microsoft by sneaking in fake Teams installers, but it turns out their stormy tactics were more of a drizzle. Kudos to Microsoft for revoking those certificates before Vanilla Tempest could rain on anyone else’s parade!

Key Points:

  • Microsoft revoked over 200 certificates used by Vanilla Tempest for fake Teams installers.
  • The group targeted various sectors using multiple ransomware payloads.
  • Vanilla Tempest distributed fake installers through SEO poisoning and fraudulent domains.
  • Microsoft ensured Defender Antivirus can detect these threats with added indicators of compromise.
  • The campaign was disrupted in early October 2025, neutralizing the threat.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?