APT29 targets Active Directory Federation Services with stealthy backdoor
The FoggyWeb post-exploitation backdoor is persistent and steals configuration databases and security token certificates.
Stay updated with breaking news from Identityserver Servicehost. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
The FoggyWeb post-exploitation backdoor is persistent and steals configuration databases and security token certificates.
The Nobelium attackers, who are responsible for the SolarWinds intrusion, have been deploying a new backdoor called FoggyWeb in targeted attacks.
December 18, 2020 Analyzing Solorigate, the compromised DLL file that started a sophisticated cyberattack, and how Microsoft Defender helps protect customers Microsoft 365 Defender Research Team Microsoft Threat Intelligence Center (MSTIC) Share UPDATE: Microsoft continues to work with partners and customers to expand our knowledge of the threat actor behind the nation-state cyberattacks that compromised the supply chain of SolarWinds and impacted multiple other organizations. Microsoft previously used ‘Solorigate’ as the primary designation for the actor, but moving forw...