TechBriefly
  • Tech
  • Business
  • Crypto
  • Science
  • Geek
  • How to
  • About
    • About TechBriefly
    • Terms and Conditions
    • Privacy Policy
    • Contact Us
    • Languages
      • 中文 (Chinese)
      • Dansk
      • Deutsch
      • Español
      • English
      • Français
      • Nederlands
      • Italiano
      • 日本语 (Japanese)
      • 한국인 (Korean)
      • Norsk
      • Polski
      • Português
      • Pусский (Russian)
      • Suomalainen
      • Svenska
No Result
View All Result
TechBriefly
Home Tech Security
Warning by Microsoft: This malware called FoggyWeb can create a permanent backdoor for intruders

Warning by Microsoft: This malware called FoggyWeb can create a permanent backdoor for intruders

Kerem GülenbyKerem Gülen
28 September 2021
in Security, Tech
Reading Time: 2 mins read
Share on FacebookShare on Twitter

Another piece of malware used by the attackers who carried out the SolarWinds software supply chain attack in December has been identified by Microsoft.

Researchers have discovered a number of modules utilized by the attack group, which Microsoft refers to as Nobelium. The US and United Kingdom officially charged the Russian Foreign Intelligence Service (SVR) hacking unit, also known as APT29, Cozy Bear, and The Dukes, with responsibility for the attack in April.

FoggyWeb can create a permanent backdoor for intruders

Warning by Microsoft: This malware called FoggyWeb can create a backdoor for intruders
Warning by Microsoft: This malware called FoggyWeb can create a backdoor for intruders

This malware called FoggyWeb creates a backdoor that the intruders employ after gaining access to a targeted server.

In this scenario, the crew employs a range of measures to steal Active Directory Federation Services (AD FS) server usernames and passwords in order to gain admin-level access. By overwriting the master boot record, an attacker can remain inside a network after a cleanup. Since April 2021, FoggyWeb has been observed in the wild, according to Microsoft.

Microsoft warns users of the malware and gives some recommendations

Ramin Nafisi from the Microsoft Threat Intelligence Center says: “Nobelium uses FoggyWeb to remotely exfiltrate the configuration database of compromised AD FS servers, decrypted token-signing certificate, and token-decryption certificate, as well as to download and execute additional components.”

“FoggyWeb is a passive and highly targeted backdoor capable of remotely exfiltrating sensitive information from a compromised AD FS server. It can also receive additional malicious components from a command-and-control (C2) server and execute them on the compromised server,” he adds.

Warning by Microsoft: This malware called FoggyWeb can create a backdoor for intruders
Warning by Microsoft: This malware called FoggyWeb can create a backdoor for intruders

This backdoor allows an attacker to exploit the Security Assertion Markup Language (SAML) token, which is utilized to make it easier for users to log into applications.

Microsoft advises potentially affected consumers to follow these three key actions: audit on-premises and cloud infrastructure for configurations, and per-user and per-application settings; remove user and app access, examine configurations, and reissue new strong credentials; and employ a hardware security module to prevent FoggyWeb from stealing secrets from AD FS servers.

Tags: attackhackhackermalwareMicrosoftsecurity
ShareTweet
Kerem Gülen

Kerem Gülen

Kerem from Turkey has an insatiable curiosity for the latest advancements in tech gadgets and a knack for innovative thinking.With 3 years of experience in editorship and a childhood dream of becoming a journalist, Kerem has always been curious about the latest tech gadgets and is constantly seeking new ways to create.As a Master's student in Strategic Communications, Kerem is eager to learn more about the ever-evolving world of technology. His primary focuses are artificial intelligence and digital inclusion, and he delves into the most current and accurate information on these topics.

Related Posts

Apple begins iPhone 18 series production testing in January

Apple begins iPhone 18 series production testing in January

24 December 2025
EA investigates AI claims in Battlefield 6 cosmetics

EA investigates AI claims in Battlefield 6 cosmetics

24 December 2025
Amazon Alexa+ will book your hotels and salons starting in 2026

Amazon Alexa+ will book your hotels and salons starting in 2026

24 December 2025
OpenAI launches Skills in Codex

OpenAI launches Skills in Codex

24 December 2025
Please login to join discussion

LATEST

How to install mods and custom content in The Sims 2

Running Python files and fixing path errors on Windows

How to boot your PC into Command Prompt for troubleshooting

How to delete a virus using Command Prompt

How to connect a PS4 controller to Steam via USB or Bluetooth

How to connect your phone to Wi-Fi and fix connection issues

Apple begins iPhone 18 series production testing in January

EA investigates AI claims in Battlefield 6 cosmetics

Amazon Alexa+ will book your hotels and salons starting in 2026

OpenAI launches Skills in Codex

TechBriefly

© 2021 TechBriefly is a Linkmedya brand.

  • Tech
  • Business
  • Science
  • Geek
  • How to
  • About
  • Privacy
  • Terms
  • Contact
  • | Network Sites |
  • Digital Report
  • LeaderGamer

Follow Us

No Result
View All Result
  • Tech
  • Business
  • Crypto
  • Science
  • Geek
  • How to
  • About
    • About TechBriefly
    • Terms and Conditions
    • Privacy Policy
    • Contact Us
    • Languages
      • 中文 (Chinese)
      • Dansk
      • Deutsch
      • Español
      • English
      • Français
      • Nederlands
      • Italiano
      • 日本语 (Japanese)
      • 한국인 (Korean)
      • Norsk
      • Polski
      • Português
      • Pусский (Russian)
      • Suomalainen
      • Svenska