Microsoft Disrupts Malware Code-Signing Service Ransomware Groups | MSSP Advisory

CriticalCredible Report
DateMay 20, 2026
📋Executive Summary
Microsoft disrupted a malware code-signing service that provided digitally signed certificates to ransomware groups including INC, Qilin, Akira, and Rhysida. The service used over 1,000 stolen code-signing certificates obtained through Microsoft's own Artifact Signing service to make malware appear legitimate on Windows systems. Attackers created fake installers for enterprise software like AnyDesk, Microsoft Teams, Putty, and Webex that bypassed security controls because they carried valid digital signatures.
⚠️Why It Matters for MSSPs
Your RMM agents and remote access tools likely whitelist signed executables, making this signing service a direct threat to your client monitoring capabilities. Every client running the affected enterprise software faces immediate risk from these signed malware installers that will bypass most endpoint protection. You need to audit what your clients downloaded recently and verify legitimacy of common business applications they rely on daily.
📬

Get notified when client-ready advisories like this are published each week.

Join the MSSP Watchlist →
🏷️Threat Category
Supply Chain

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.