Microsoft has disrupted a malware-signing service used to distribute ransomware in multiple campaigns. The company said the operation targeted a network of accounts and digital certificates that attackers relied on to make malicious software appear legitimate to security tools. The action focused on infrastructure that supplied signed executables for ransomware groups. According to Microsoft, the certificates allowed attackers to bypass some security checks and increase the success rate of their payloads. The company did not name the specific ransomware families or groups tied to the service.
Details of the Operation
Microsoft reported that es