Vanilla Tempest Ransomware Operation is a threat campaign tracked by ThreatCluster, appearing in 1 threat cluster built from 1 intelligence report mention.
Vanilla Tempest Ransomware Operation is a threat campaign tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed May 19, 2026; most recent activity May 19, 2026.
On May 19, 2026, Microsoft disrupted Fox Tempest, a malware-signing-as-a-service (MSaaS) operation that provided over 1,000 fraudulent code-signing certificates to cybercriminals, enabling them to disguise malware as…
Vanilla Tempest Ransomware Operation is a threat campaign tracked by ThreatCluster, appearing in 1 threat cluster built from 1 intelligence report mention.
The most recent intelligence report mentioning Vanilla Tempest Ransomware Operation on ThreatCluster is dated May 19, 2026.
Across ThreatCluster reporting, Vanilla Tempest Ransomware Operation most frequently co-occurs with Vanilla Tempest, Malware, Ransomware, Crazy Evil Traffers Crypto-theft Campaign, Azure, among 12 tracked related entities.
The most significant recent cluster is “Microsoft Disrupts Fox Tempest Malware-Signing Service for Ransomware Gangs” (33 articles · Updated May 19, 2026). Vanilla Tempest Ransomware Operation appears across 1 threat cluster in total, listed above with sources.
Vanilla Tempest Ransomware Operation appears in 1 intelligence report mention across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.