FoggyWeb
S0661 · Windows
FoggyWeb is a passive and highly-targeted backdoor capable of remotely exfiltrating sensitive information from a compromised Active Directory Federated Services (AD FS) server. It has been used by APT29 since at least early April 2021.
ATT&CK S0661
Sigma rules0
YARA rules0
Live IOCs0