FoggyWeb is a highly targeted post-exploitation backdoor used by the Russian state-linked espionage actor tracked as NOBELIUM, APT29, Cozy Bear, and Midnight Blizzard. It is designed for compromise of on-premises Active Directory Federation Services (AD FS) infrastructure after the actor has already obtained administrative control of the server. Its primary purpose is to steal identity material and maintain covert access to federated authentication environments, enabling follow-on abuse of trust relationships and cloud access.
FoggyWeb targets AD FS servers and operates inside the AD FS service context to access sensitive federation data. Reported capabilities include retrieving AD FS configuration data, extracting token-signing and token-decryption certificates, and remotely exfiltrating sensitive information from the compromised server. It can also receive and execute additional malicious components, including in-memory execution of .NET assemblies and dynamic compilation and execution of attacker-supplied source code. The malware has also been observed configuring custom HTTP listeners to passively monitor and intercept inbound HTTP GET and POST requests matching actor-defined URI patterns, supporting covert command-and-control and collection.
Operationally, FoggyWeb has been associated with stealth-focused loader behavior. Its loader has used DLL search order hijacking to force the AD FS service process to load malicious code in place of a legitimate library, and it has reflectively loaded .NET payloads into memory within the same application domain as legitimate AD FS code. The malware has also been disguised as benign-looking Visual Studio-related resources to reduce suspicion and evade detection.
FoggyWeb is closely associated with the post-SolarWinds intrusion activity attributed to NOBELIUM and has been linked to efforts to obtain the cryptographic material necessary for identity abuse against federated environments. Its victimology is therefore aligned with APT29’s broader espionage targeting, which has historically included government, diplomatic, policy, technology, and other strategically significant organizations. FoggyWeb is best understood as specialized identity-infrastructure malware intended to convert an AD FS server compromise into durable access, sensitive data theft, and downstream authentication abuse.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
另一方面,如果攻擊者已獲得 AD FS 的主機控制權,就可以透過 .NET Reflection 竊取金鑰。此手法就如同 NOBELIUM 的 FoggyWeb 惡意程式。該惡意程式也有被研究人員關聯到 Solorigate APT 事件
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Astaroth uses the LoadLibraryExW() function to load additional modules. Attor's dispatcher can execute additional plugins by loading the respective DLLs. ... LightSpy's main executable and module .dylib binaries are loaded using ... dlopen() ... dlsym() ... RotaJakiro uses ... .so files ... using dlopen() and dlsym().
...uses the LoadLibraryExW() function to load additional modules... execute additional plugins by loading the respective DLLs... loaded and executed DLLs in memory during runtime... loads a dynamic library (.dylib file) using dlopen() and obtains a function pointer... using dlopen() and dlsym()... calls LoadLibrary then executes exports from a DLL.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Adversaries may attempt to make payloads difficult to discover and analyze by delivering files to victims as uncompiled code. Text-based source code files may subvert analysis and scrutiny from protections targeting executables/binaries. These payloads will need to be compiled before execution; typically via native utilities such as ilasm.exe, csc.exe, or GCC/MinGW.
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
Akira has used legitimate names and locations for files to evade defenses.
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
...uses the LoadLibraryExW() function to load additional modules... execute additional plugins by loading the respective DLLs... loaded and executed DLLs in memory during runtime... loads a dynamic library (.dylib file) using dlopen() and obtains a function pointer... using dlopen() and dlsym()... calls LoadLibrary then executes exports from a DLL.
FoggyWeb can retrieve configuration data from a compromised AD FS server.
MITRE ATT&CK Mappings: APT29 Credential Access T1606: Forge Web Credentials .001: Web Cookies .002: SAML Tokens
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, enumerating PIDs, checking for specific process names, or using APIs such as CreateToolhelp32Snapshot and commands such as tasklist and ps.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A stealthy backdoor for compromised AD FS servers that exfiltrates sensitive data and can receive additional payloads from C2.
AD FS malware used by Midnight Blizzard.
Malware associated with NOBELIUM that steals AD FS-related key material using techniques such as .NET reflection, enabling downstream GoldenSAML-style abuse.
A post-exploitation capability used against compromised AD FS servers to exfiltrate configuration databases, decrypt token-signing and token-decryption certificates, and download and execute additional malware components.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.