Vanilla Tempest Ransomware Operation — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
May 19, 2026
Last Seen
May 19, 2026

Vanilla Tempest Ransomware Operation is a threat campaign tracked by ThreatCluster, appearing in 1 threat cluster built from 1 intelligence report mention.

Vanilla Tempest Ransomware Operation is a threat campaign tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed May 19, 2026; most recent activity May 19, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • Cybercrime service disrupted for abusing Microsoft platform to sign malware — Bleepingcomputer · May 19, 2026

Frequently asked questions

What is Vanilla Tempest Ransomware Operation?

Vanilla Tempest Ransomware Operation is a threat campaign tracked by ThreatCluster, appearing in 1 threat cluster built from 1 intelligence report mention.

Is Vanilla Tempest Ransomware Operation still active?

The most recent intelligence report mentioning Vanilla Tempest Ransomware Operation on ThreatCluster is dated May 19, 2026.

What is Vanilla Tempest Ransomware Operation associated with?

Across ThreatCluster reporting, Vanilla Tempest Ransomware Operation most frequently co-occurs with Vanilla Tempest, Malware, Ransomware, Crazy Evil Traffers Crypto-theft Campaign, Azure, among 12 tracked related entities.

What are the latest developments involving Vanilla Tempest Ransomware Operation?

The most significant recent cluster is “Microsoft Disrupts Fox Tempest Malware-Signing Service for Ransomware Gangs” (33 articles · Updated May 19, 2026). Vanilla Tempest Ransomware Operation appears across 1 threat cluster in total, listed above with sources.

How much reporting does ThreatCluster have on Vanilla Tempest Ransomware Operation?

Vanilla Tempest Ransomware Operation appears in 1 intelligence report mention across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown