FoggyWeb

S0661

Malware.View on attack.mitre.org

About this malware

FoggyWeb is a passive and highly-targeted backdoor capable of remotely exfiltrating sensitive information from a compromised Active Directory Federated Services (AD FS) server. It has been used by APT29 since at least early April 2021.

Techniques used21

Procedure examples21

TechniqueProcedure example
T1005
Data from Local System

FoggyWeb can retrieve configuration data from a compromised AD FS server.

T1027.004
Compile After Delivery

FoggyWeb can compile and execute source code sent to the compromised AD FS server via a specific HTTP POST.

T1027.013
Encrypted/Encoded File

FoggyWeb has been XOR-encoded.

T1036
Masquerading

FoggyWeb can masquerade the output of C2 commands as a fake, but legitimately formatted WebP file.

T1036.005
Match Legitimate Resource Name or Location

FoggyWeb can be disguised as a Visual Studio file such as `Windows.Data.TimeZones.zh-PH.pri` to evade detection. Also, FoggyWeb's loader can mimic a genuine `dll` file that carries out the same import functions as the legitimate Windows `version.dll` file.

T1040
Network Sniffing

FoggyWeb can configure custom listeners to passively monitor all incoming HTTP GET and POST requests sent to the AD FS server from the intranet/internet and intercept HTTP requests that match the custom URI patterns defined by the actor.

T1041
Exfiltration Over C2 Channel

FoggyWeb can remotely exfiltrate sensitive information from a compromised AD FS server.

T1057
Process Discovery

FoggyWeb's loader can enumerate all Common Language Runtimes (CLRs) and running Application Domains in the compromised AD FS server's Microsoft.IdentityServer.ServiceHost.exe process.

T1071.001
Web Protocols

FoggyWeb has the ability to communicate with C2 servers over HTTP GET/POST requests.

T1083
File and Directory Discovery

FoggyWeb's loader can check for the FoggyWeb backdoor .pri file on a compromised AD FS server.

T1105
Ingress Tool Transfer

FoggyWeb can receive additional malicious components from an actor controlled C2 server and execute them on a compromised AD FS server.

T1106
Native API

FoggyWeb's loader can use API functions to load the FoggyWeb backdoor into the same Application Domain within which the legitimate AD FS managed code is executed.

T1129
Shared Modules

FoggyWeb's loader can call the load() function to load the FoggyWeb dll into an Application Domain on a compromised AD FS server.

T1140
Deobfuscate/Decode Files or Information

FoggyWeb can be decrypted in memory using a Lightweight Encryption Algorithm (LEA)-128 key and decoded using a XOR key.

T1550
Use Alternate Authentication Material

FoggyWeb can allow abuse of a compromised AD FS server's SAML token.

View all 21 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. MSTIC FoggyWeb September 2021 Open source
    Ramin Nafisi. (2021, September 27). FoggyWeb: Targeted NOBELIUM malware leads to persistent backdoor. Retrieved October 4, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.