Microsoft has revealed another piece of malware used by the attackers behind the SolarWinds software supply chain attack discovered in December.

See also: Microsoft Outlook: New way to compose messages on the go
Security researchers have discovered numerous modules used by the attack group, which Microsoft calls Nobelium. The US and UK in April officially blamed the attack on the hacking group of the Russian Foreign Intelligence Service (SVR), also known as APT29, Cozy Bear and The Dukes.
Microsoft in March revealed the GoldMax, GoldFinder and Sibot components from Nobelium, based on other malware from the group, including Sunburst/Solarigate, Teardrop and Sunspot.
The newly discovered malware, dubbed FoggyWeb by Microsoft, is a backdoor used by hackers after a targeted server has already been compromised.
See also: Flaw found in Microsoft WPBT: Which devices does it affect?
In this case, the group uses various tactics to steal network usernames and passwords to gain administrator-level access to Active Directory Federation Services servers, which gives them access to the identity and access management infrastructure to control user access to applications and resources. This allows attackers to remain within a network even after a cleanup. FoggyWeb has been in use by hackers since April 2021, according to Microsoft.
The backdoor allows abuse of the Security Assertion Markup Language (SAML) token, which is used to help users more easily authenticate to applications.
Microsoft recommends that potentially affected customers take three key steps: reviewing their infrastructure and cloud infrastructure for per-user and per-application configurations and settings, removing user and application access, auditing configurations and reissuing new, strong credentials, and using a hardware security module to prevent FoggyWeb from stealing secrets from AD FS servers.
Useful Tip: How to download and use Microsoft Word for free
Microsoft revealed more Noeblium infection tools in May, including EnvyScout, BoomBox, NativeZone, and VaporRage, as well as a phishing campaign promoted to a legitimate US email-marketing service.
Information source: zdnet.com
