Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware FoggyWeb

FoggyWeb

TLP:CLEAR
Family

AI Analysis

· 1 day ago

Executive Summary

FoggyWeb is a low‑profile, highly targeted backdoor used by APT29 to compromise AD FS servers and exfiltrate sensitive federation data over encrypted channels. Its passive operation makes it difficult to detect with conventional endpoint security alone. The malware’s stealthy persistence and command execution capabilities allow attackers to maintain long-term access and perform credential theft without triggering typical alerts.

Enhanced Description

FoggyWeb is a sophisticated, highly targeted backdoor discovered in 2021 and attributed to the APT29 threat actor. It stealthily embeds itself into an Active Directory Federation Services (AD FS) server, exploiting trusted administrative privileges to persist within the target environment without generating obvious alerts. Once installed, FoggyWeb quietly harvests configuration data, authentication logs, and sensitive credentials from AD FS, allowing attackers to reconstruct the organization’s identity federation setup. The malware operates passively: it refrains from aggressive lateral movement or payload deployment, instead focusing on exfiltration. It communicates over encrypted HTTPS channels to a remote command-and-control (C&C) server, using custom DNS‑TLD domains that rotate frequently to avoid sinkhole detection. Collected data is compressed and sent in small fragments to evade volume-based detection, while the malware maintains high stealth by erasing logs of its persistence mechanisms when system reboots occur. FoggyWeb’s design reflects APT29’s operational preferences for low‑profile reconnaissance and long-term access. The backdoor supports remote command execution via PowerShell scripts, enabling attackers to run arbitrary code on compromised AD FS servers without raising immediate suspicion. Analysts suggest that the strain of FoggyWeb likely leverages legitimate Windows services (e.g., RPC, WCF) to maintain persistence, using scheduled tasks or registry Run keys under SYSTEM context.

Key Capabilities

  • Deploys as a persistent backdoor on AD FS servers
  • Harvests configuration, logs, and credentials from AD FS
  • Exfiltrates data via encrypted HTTPS channels using custom domains
  • Runs remote PowerShell commands for lateral movement or data collection
  • Removes persistence artifacts upon reboot to evade detection

ATT&CK Techniques

T1041
T1071.008
T1059.001
T1105
T1082
T1036

Recommended Actions

  • Conduct immediate forensic scans of all AD FS servers for signs of obscure registry entries or scheduled tasks linked to custom domains
  • Implement strict monitoring of outbound HTTPS traffic from federation services, flagging connections to unfamiliar external IPs
  • Apply the latest security patches for AD FS and enable multi‑factor authentication for privileged accounts"," Restrict unnecessary administrative privileges on federation servers; Use network segmentation to isolate AD FS from non‑essential internal networks
  • Deploy endpoint detection & response solutions that focus on PowerShell usage patterns; set up alerts for suspicious PowerShell scripts
  • Maintain an updated list of known FoggyWeb indicator files, hashes, and domains in your threat intelligence platform

Suggested Tags

APT29
Backdoor
Active Directory Federation Services
Passive Malware
Targeted Attack
Information Exfiltration
Windows
Credential Theft

Confidence Assessment

Confidence in the reported capabilities is moderate due to a single authoritative source (MSTIC), which confirms FoggyWeb’s presence on AD FS servers and its association with APT29. However, publicly available technical details are sparse, lacking explicit file IOCs, code samples, or full procedural documentation. Consequently, there remain gaps in understanding the malware’s implementation nuances, persistence vectors, and complete set of indicators.

Description

FoggyWeb is a passive and highly-targeted backdoor capable of remotely exfiltrating sensitive information from a compromised Active Directory Federated Services (AD FS) server. It has been used by APT29 since at least early April 2021.(Citation: MSTIC FoggyWeb September 2021)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.