Microsoft warns: Active Directory FoggyWeb malware being actively used by Nobelium gang
- Reference: 1632825862
- News link: https://www.theregister.co.uk/2021/09/28/active_directory_foggyweb_malware/
- Source link:
The FoggyWeb malware, Microsoft has declared, is designed to target Microsoft Active Directory Federation Services (AD FS) servers, exfiltrating credentials, configuration databases, decrypted token-signing and token-decryption certificates, and to download additional components to set up a permanent backdoor and attack the network more widely.
"Because FoggyWeb is loaded into the same application domain as the AD FS managed code, it gains programmatical access to the legitimate AD FS classes, methods, properties, fields, objects, and components that are subsequently leveraged by FoggyWeb to facilitate its malicious operations," Ramin Nafisi, Microsoft Threat Intelligence Centre researcher, wrote in an [1]analysis of the malware.
[2]
"FoggyWeb is also AD FS version-agnostic; it does not need to keep track of legacy versus modern configuration table names and schemas, named pipe names, and other version-dependent properties of AD FS."
[3]
[4]
Systems compromised by the malware will leak credentials and other private data, Microsoft has confirmed, while providing attackers with a remote-controlled backdoor into the server – with a command-and-control system cleverly disguised as HTTP GET and POST requests.
"Once Nobelium obtains credentials and successfully compromises a server, the actor relies on that access to maintain persistence and deepen its infiltration using sophisticated malware and tools," Nafisi explained. "Nobelium uses FoggyWeb to remotely exfiltrate the configuration database of compromised AD FS servers, decrypted token-signing certificate, and token-decryption certificate, as well as to download and execute additional components."
[5]
Nobelium, which is believed to be linked to the Russian government, has been fingered for [6]the 2020 attack on SolarWinds' Orion IT monitoring platform, which was then used as a jumping-off point to infiltrate US government networks – including the [7]US courts system .
[8]Here's 30 servers Russian intelligence uses to fling malware at the West, beams RiskIQ
[9]Mega-distie SYNNEX attacked and Microsoft cloud accounts it tends tampered
[10]Security researcher says attacks on Russian government have Chinese fingerprints – and typos, too
[11]Us? Pwn SolarWinds? With our reputation? Russian spy chief makes laughable denial of supply chain attack
More recently the group succeeded in a phishing attack on [12]Microsoft's support desk , retrieving private customer data which the company confirmed included "information regarding... Microsoft Services subscriptions" and was used "in some cases" to launch further "highly-targeted attacks as part of [a] broader campaign."
"Protecting AD FS servers is key to mitigating Nobelium attacks," Nafisi concluded in his report. "Detecting and blocking malware, attacker activity, and other malicious artifacts on AD FS servers can break critical steps in known Nobelium attack chains."
To help, the company has published a [13]best practices guide which includes restricting account rights to AD FS access, requiring the use of multi-factor authentication (MFA), using host firewalls to limit on-network access, and the suggestion to "remove unnecessary protocols and Windows features."
The FoggyWeb malware is detected in Microsoft Defender Antivirus as Trojan:Win32/FoggyWeb.A!dha and Trojan:MSIL/FoggyWeb.A!dha for the loader and backdoor respectively, while the [14]security report has additional indicators of compromise (IOCs) and a hunting query for Microsoft Defender for Endpoint.
[15]
In a message posted to his personal [16]Twitter account, Microsoft chief security adviser Roger Halbheer had a brief and somewhat eyebrow-raising piece of additional advice: "Why are there still AD FS servers without HSM [Hardware Security Modules]? Best would be to get off AD FS but if you still use it, move your keys to an HSM."
Microsoft confirmed that it has evidence of FoggyWeb in active use since at least April this year, and that it has contacted all those customers it found to be "targeted or compromised by this activity" – but did not respond to a request for comment on how many infections it had found nor their geographic distribution in time for publication. ®
Get our [17]Tech Resources
[1] https://www.microsoft.com/security/blog/2021/09/27/foggyweb-targeted-nobelium-malware-leads-to-persistent-backdoor/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YVM8UkmHcnfI194AaknpogAAABQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YVM8UkmHcnfI194AaknpogAAABQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YVM8UkmHcnfI194AaknpogAAABQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YVM8UkmHcnfI194AaknpogAAABQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2020/12/14/solarwinds_fireeye_cozybear_us_government/
[7] https://www.theregister.com/2021/01/08/solarwinds_court_docs/
[8] https://www.theregister.com/2021/07/30/riskiq_reveals_30_svr_apt29_c2_servers/
[9] https://www.theregister.com/2021/07/07/synnex_rnc_microsoft_attack/
[10] https://www.theregister.com/2021/06/09/mail_o_malware_maybe_chinese/
[11] https://www.theregister.com/2021/05/18/russian_spymaster_solarwinds/
[12] https://www.theregister.com/2021/06/26/in_brief_security/
[13] https://docs.microsoft.com/windows-server/identity/ad-fs/deployment/best-practices-securing-ad-fs
[14] https://www.microsoft.com/security/blog/2021/09/27/foggyweb-targeted-nobelium-malware-leads-to-persistent-backdoor/
[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YVM8UkmHcnfI194AaknpogAAABQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[16] https://twitter.com/rhalbheer/status/1442747291358670849
[17] https://whitepapers.theregister.com/
Re: Microsoft Active Directory
This isn't Active Directory. Its Federation Services, the FS part in ADFS. They want you moving to Azure AD which has the functionality of ADFS for example AD connect.
Obvious reason why they want that and are not providing a similar solution on prem, its not over security concerns.
so THAT is why I have been getting more e-mail-spam lately
From the article: More recently the group succeeded in a phishing attack on Microsoft's support desk, retrieving private customer data which the company confirmed included "information regarding... Microsoft Services subscriptions" and was used "in some cases" to launch further "highly-targeted attacks as part of [a] broader campaign."
does 'a broader campaign' include (at times) a dozen or more (lame) spear-phishing e-mails per day with the usual payloads and malicious links? The frequency of these things has gone up 10 fold over the last couple of weeks... on the e-mail address I use with my (soon to expire, and I may not renew) MSDN subscription.
(good thing I do not open the obvious malicius attachments nor view as HTML on a windows-based mail reader)
There has been major eventful development ... for media to deal with
The FoggyWeb malware, Microsoft has declared, is designed to target Microsoft Active Directory Federation Services (AD FS) servers, exfiltrating credentials, configuration databases, decrypted token-signing and token-decryption certificates, and to download additional components to set up a permanent backdoor and attack the network more widely.
And what would Microsoft like to do with Variants that enhance networks widely everywhere?
That wouldn't be an attack whenever Virtually a Future AIdDevelopment for toasting and roasting and hosting live beta testing with Microsoft AD FS servering ACTive Assets for Browser Deployments/Systems Engagements ......... A Heavenly Captivating Capture to Surrender and Submit Wholeheartedly to for the Benefits Derived from an Immaculate Satisfaction Borne of the Bond Presenting and Pioneering Perfect Happiness.
I Kid U Not :-)
Would that require one make and/or take a Quantum Leap ‽ . :-) for Ennobling and Enabling Nobel Prize Territory Gains ........ Providing Genius Advantage ‽ .
El Regers would certainly surely like and love to know ........ given what is So Clearly Offered ‽ .
Microsoft Active Directory
It was only a matter of time before it became an active threat.
Even the Borkzilla specialist wants you to migrate to something else.
Telling.