Threat Advisory

FoggyWeb: Targeted NOBELIUM malware leads to persistent backdoor

Threat: APT
Criticality: High
[subscribe_to_unlock_form]

Summary:

Microsoft continues to work with partners and customers to track the threat actor refer to as NOBELIUM, the actor behind the SUNBURST backdoor, TEARDROP malware, and related components. It suspected that NOBELIUM can draw from significant operational resources often showcased in their campaigns, including custom-built malware and tools. In March 2021, we profiled NOBELIUM’s GoldMax, GoldFinder, and Sibot malware, which it uses for layered persistence. We then followed that up with another post in May, when we analysed the actor’s early-stage toolset comprising EnvyScout, BoomBox, NativeZone, and VaporRage.[/subscribe_to_unlock_form]

Summary:

Microsoft continues to work with partners and customers to track the threat actor refer to as NOBELIUM, the actor behind the SUNBURST backdoor, TEARDROP malware, and related components. It suspected that NOBELIUM can draw from significant operational resources often showcased in their campaigns, including custom-built malware and tools. In March 2021, we profiled NOBELIUM’s GoldMax, GoldFinder, and Sibot malware, which it uses for layered persistence. We then followed that up with another post in May, when we analysed the actor’s early-stage toolset comprising EnvyScout, BoomBox, NativeZone, and VaporRage.[emaillocker id="1283"]

NOBELIUM employs multiple tactics to pursue credential theft with the objective of gaining admin-level access to Active Directory Federation Services (AD FS) servers. Once NOBELIUM obtains credentials and successfully compromises a server, the actor relies on that access to maintain persistence and deepen its infiltration using sophisticated malware and tools. NOBELIUM uses FoggyWeb to remotely exfiltrate the configuration database of compromised AD FS servers, decrypted token-signing certificate, and token-decryption certificate, as well as to download and execute additional components. Use of FoggyWeb has been observed in the wild as early as April 2021.

          Fig: communication with the FoggyWeb backdoor located on a compromised internet-facing AD FS server.

References:

The following reports contain further technical details:

https://www.microsoft.com/security/blog/2021/09/27/foggyweb-targeted-nobelium-malware-leads-to-persistent-backdoor/

[/emaillocker]
crossmenu