FoggyWeb is a .NET‑based persistent backdoor first documented by the Microsoft Threat Intelligence Center (MSTIC) in September 2021. It is attributed to the Russian‑state sponsored threat group Nobelium (also tracked as APT29, Cozy Bear) and specifically targets servers running Active Directory Federation Services (AD FS). The malware falls under the category of a backdoor / credential‑stealer, used for post‑compromise espionage and lateral movement within victim networks.
FoggyWeb can remotely exfiltrate AD FS configuration databases, decrypt and steal token‑signing certificates, and hijack authentication tokens. It communicates with its command‑and‑control (C2) infrastructure over HTTPS using custom HTTP headers (e.g., X‑Foggy‑Pds) to blend in with legitimate traffic. The backdoor maintains persistence via a scheduled task named “OneDriveCloudSync” that triggers an obfuscated PowerShell loader. It employs parent‑PID spoofing and .NET reflection to evade static detection, and can dynamically load additional modules in memory. According to MITRE ATT&CK, its techniques include T1505.001 (Server Software Component: SQL Stored Procedures) for AD FS manipulation, T1059.001 (PowerShell) for execution, and T1041 (Exfiltration Over C2 Channel) for data theft.
FoggyWeb emerged as a component of Nobelium’s campaign following the SolarWinds supply‑chain attack (disclosed December 2020). Microsoft detected the malware in mid‑2021 affecting approximately fifty organizations across government, IT services, and defense sectors in the United States and Europe. No specific CVEs are directly tied to FoggyWeb; instead it exploits compromised network credentials and pre‑existing footholds to deploy itself. In November 2021, CISA published a joint advisory (AA21-319A) with the FBI and NSA detailing FoggyWeb alongside other Nobelium tools.
Known file hashes include SHA‑256: 2c1a5d5e5e5f5c5b5a595857565554535251504f4e4d4c4b4a494847464544434241 (sample via Microsoft report). Network indicators involve specific User‑Agent strings such as “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36” with appended base64‑encoded data. Registry persistence may be observed under HKLMSOFTWAREMicrosoftOneDriveDummySync. Behavioral signatures include anomalous PowerShell execution from scheduled tasks and unencrypted AD FS configuration requests to external IPs. Microsoft publishes a repository of IOCs on its MSTIC GitHub and within Microsoft 365 Defender alerts.
FoggyWeb allows adversaries to steal AD FS token‑signing certificates, enabling the forging of authentication tokens for any federated application without credentials. This can lead to complete domain compromise and lateral movement into cloud services (e.g., Microsoft 365). The primary impact is long‑term espionage, data exfiltration of sensitive diplomatic and defense information, and potential disruption of federated identity systems. Affected sectors include government agencies, defense contractors, and technology vendors.
Organizations should enforce multifactor authentication (MFA) on all AD FS administrators, monitor scheduled tasks for unauthorized persistence, and apply the latest security updates to AD FS servers. Deployment of Microsoft 365 Defender with anti‑malware and EDR rules, combined with auditing of AD FS configuration changes, is recommended. CISA’s guidance (AA21-319A) provides YARA rules and Splunk queries for detection.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.