FoggyWeb — Malware Profile

FoggyWeb is a passive and highly-targeted backdoor capable of remotely exfiltrating sensitive information from a compromised Active Directory Federated Services (AD FS) server. It has been used by APT29 since at least early April 2021.

MITRE ATT&CK techniques (21)

Attributed threat actors

Read the full analysis on IntelFusions