Executive Summary
FoggyWeb is a low‑profile, highly targeted backdoor used by APT29 to compromise AD FS servers and exfiltrate sensitive federation data over encrypted channels. Its passive operation makes it difficult to detect with conventional endpoint security alone. The malware’s stealthy persistence and command execution capabilities allow attackers to maintain long-term access and perform credential theft without triggering typical alerts.
Enhanced Description
FoggyWeb is a sophisticated, highly targeted backdoor discovered in 2021 and attributed to the APT29 threat actor. It stealthily embeds itself into an Active Directory Federation Services (AD FS) server, exploiting trusted administrative privileges to persist within the target environment without generating obvious alerts. Once installed, FoggyWeb quietly harvests configuration data, authentication logs, and sensitive credentials from AD FS, allowing attackers to reconstruct the organization’s identity federation setup. The malware operates passively: it refrains from aggressive lateral movement or payload deployment, instead focusing on exfiltration. It communicates over encrypted HTTPS channels to a remote command-and-control (C&C) server, using custom DNS‑TLD domains that rotate frequently to avoid sinkhole detection. Collected data is compressed and sent in small fragments to evade volume-based detection, while the malware maintains high stealth by erasing logs of its persistence mechanisms when system reboots occur. FoggyWeb’s design reflects APT29’s operational preferences for low‑profile reconnaissance and long-term access. The backdoor supports remote command execution via PowerShell scripts, enabling attackers to run arbitrary code on compromised AD FS servers without raising immediate suspicion. Analysts suggest that the strain of FoggyWeb likely leverages legitimate Windows services (e.g., RPC, WCF) to maintain persistence, using scheduled tasks or registry Run keys under SYSTEM context.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the reported capabilities is moderate due to a single authoritative source (MSTIC), which confirms FoggyWeb’s presence on AD FS servers and its association with APT29. However, publicly available technical details are sparse, lacking explicit file IOCs, code samples, or full procedural documentation. Consequently, there remain gaps in understanding the malware’s implementation nuances, persistence vectors, and complete set of indicators.
FoggyWeb is a passive and highly-targeted backdoor capable of remotely exfiltrating sensitive information from a compromised Active Directory Federated Services (AD FS) server. It has been used by APT29 since at least early April 2021.(Citation: MSTIC FoggyWeb September 2021)