Malware signing: When trust becomes an attack surface
How cybercriminals use stolen, fraudulent, and commercialized code-signing certificates to make malware appear legitimate and bypass traditional trust controls.
Key takeaways
- Malware signing is the practice of using legitimate-looking digital certificates to make malicious software appear trustworthy.
- Signed malware may trigger fewer warnings and can evade security tools that rely heavily on reputation and publisher trust.
- Attackers obtain signing credentials through theft, fraud, underground markets, and specialized malware-signing services.
- Microsoft's disruption of the Fox Tempest operation highlights the growing commercialization of malware signing.
- Organizations should treat digital signatures as one security signal, not proof that software is safe.
- Behavior-based detection, threat hunting and MDR/XDR services can help identify malicious activity even when malware is legitimately signed.
Why digital certificates matter
Digital code-signing certificates play a critical role in the software ecosystem. When a software publisher signs an application, the certificate serves two important purposes: It identifies the publisher and verifies that the software has not been modified since it was signed. Operating systems, browsers, endpoint protection tools, and users all rely on these signals to determine whether software should be trusted.
This trust model benefits everyone. Developers can prove that their software is authentic, users can install applications with greater confidence and security tools can use certificate information as one factor when evaluating risk. In a world where millions of software packages are downloaded every day, digital signatures help establish a foundation of trust. Unfortunately, attackers have learned how to exploit that foundation.
What is malware signing?
Malware signing is the practice of applying a valid digital signature to malicious software. Rather than triggering warnings associated with unknown or unsigned files, signed malware appears to come from a legitimate source. Attackers accomplish this by using stolen certificates, purchasing certificates on underground markets or fraudulently obtaining new certificates through compromised or fake identities.
When malware carries a valid signature, it may generate fewer warnings, gain a stronger reputation score, blend in with legitimate software, and in some cases bypass controls that rely heavily on publisher trust. The malware itself remains malicious, but it inherits some of the credibility associated with the certificate.
This is why signed malware can be especially dangerous. Traditional malware often has to evade detection. Signed malware attempts to avoid suspicion altogether by exploiting existing trust mechanisms.
The rise of malware-signing-as-a-service
Like many aspects of cybercrime, malware signing has become commercialized. Rather than obtaining certificates themselves, attackers can purchase malware-signing services from specialized providers.
These malware-signing-as-a-service (MSaaS) operations allow customers to submit malicious files and receive back signed versions that are more likely to evade security checks and user scrutiny. In effect, the service is selling trust.
This specialization is part of a broader trend in cybercrime. One group develops malware, another gains initial access to victim networks, another operates ransomware campaigns, and yet another provides signing services. By breaking attacks into specialized functions, cybercriminals can operate more efficiently and lower the barriers to entry for less sophisticated actors.
Case in point: Fox Tempest
One of the most significant recent examples of this trend is Fox Tempest, a malware-signing-as-a-service operation disrupted by Microsoft in May 2026. According to Microsoft, Fox Tempest abused Microsoft Artifact Signing to generate fraudulent, short-lived code-signing certificates that allowed malware to appear legitimately signed. The operation reportedly created more than 1,000 certificates and established hundreds of Azure tenants and subscriptions to support its activities.
Microsoft linked the service to malware and ransomware operations involving families such as Oyster, Lumma Stealer, Vidar, and Rhysida. Customers could upload malicious files and receive signed binaries that appeared more trustworthy to users and security systems.
What makes the Fox Tempest takedown noteworthy is that Microsoft targeted a key enabler rather than a single ransomware group. The company revoked more than 1,000 certificates, seized infrastructure associated with the operation, took offline hundreds of virtual machines, and disrupted the service's signing portal.
How organizations can defend against signed malware
Clearly, you can no longer assume that signed equals safe. Digital signatures remain valuable, but they should be treated as just one signal among many. You should prioritize behavior-based detection technologies that monitor what software does rather than relying solely on whether it is signed.
Many organizations are supplementing traditional prevention technologies with managed detection and response (MDR) and extended detection and response (XDR) services that can identify suspicious behavior after execution. By combining endpoint, network, cloud, and identity telemetry with human-led threat hunting and investigation, services such as Barracuda Managed XDR can help detect signed malware that would otherwise blend in with legitimate activity and provide rapid response when threats are discovered.
Security teams should also strengthen application-control policies. Instead of allowing software simply because it carries a valid certificate, organizations should consider additional factors such as file reputation, source, expected behavior, and known-good publishers. Newly issued or rarely seen certificates may warrant additional scrutiny.
Other important protections include:
- Monitoring for suspicious or newly observed certificates
- Consuming certificate-revocation and threat-intelligence feeds
- Blocking downloads from untrusted or newly registered domains
- Training users that a valid signature does not guarantee legitimacy
- Focusing detection efforts on post-execution behaviors such as persistence, privilege escalation, lateral movement, and command-and-control communications
Trust, but verify
Digital certificates remain a critical component of software security, and legitimate code signing continues to provide significant benefits. The problem is not the technology itself. The problem is that attackers have found ways to exploit the trust those certificates create.
The Fox Tempest disruption demonstrates both the growing industrialization of cybercrime and the importance of targeting the services that enable attacks at scale. For defenders, the lesson is clear: Trust signals matter, but they should never be the final deciding factor. In today's threat landscape, organizations must verify not just who signed the software, but what that software actually does once it runs.
Email Threats Report 2026
Descubra cómo la IA y el phishing-as-a-service están transformando el panorama de amenazas de correo electrónico y cómo mantenerse protegido.
Suscríbase al blog de Barracuda.
Regístrese para recibir Threat Spotlight, comentarios de la industria y más.
El informe sobre amenazas globales de Managed XDR
Conclusiones clave sobre las tácticas que utilizan los atacantes para atacar a las organizaciones y los puntos débiles de seguridad que intentan explotar