Full Report
On 2022-08-22, a campaign was reported, involving APT29, gaining initial access via , while using Add attacker-controlled IdP via ADFS access, Disable logging, MFA enrollment, Auth token signing via Golden SAML, Auth token signing via ADFS access,.
Analysis Summary
# Threat Actor: APT29
## Attribution & Identity
**Actor Identification:** APT29 (also known by FireEye/Mandiant as Nobelium, and tracked by other names such as Cozy Bear, The Dukes, and Midnight Blizzard).
**Known Aliases & Associated Groups:** Nobelium, Cozy Bear, The Dukes, Midnight Blizzard.
## Activity Summary
A campaign reported on **2022-08-22** specifically targeted **Microsoft 365** environments. The primary focus of the activity described seems to center on persistent cloud access and maintaining stealth within the cloud infrastructure.
## Tactics, Techniques & Procedures
This campaign demonstrated advanced techniques focused on authentication compromise:
- Gaining initial access via **Add attacker-controlled IdP via ADFS access**.
- **Disable logging** to cover tracks.
- **MFA enrollment** (likely for maintaining persistence or bypassing controls).
- **Auth token signing via Golden SAML**.
- **Auth token signing via ADFS access**.
## Targeting
- **Sectors:** Implied targeting of organizations utilizing Microsoft 365 (likely broad, focusing on entities where M365 is critical infrastructure).
- **Geography:** Not specified in the provided context.
- **Victims:** Not specifically named in the provided context, but the activity centers on Microsoft 365 tenants.
## Tools & Infrastructure
- **Malware Families Used:** Not explicitly mentioned in the context provided.
- **Infrastructure:** Not explicitly mentioned in the context provided.
## Implications
APT29 continues to exhibit a high level of sophistication, focusing persistence and access within cloud service provider environments (specifically Microsoft 365). The use of Golden SAML and ADFS manipulation indicates a focus on deeply compromising federated identity systems to achieve long-term, stealthy remote access.
## Mitigations
Defense recommendations should focus heavily on:
- Strong monitoring and alerting for changes to Federation/ADFS settings (especially IdP configuration changes).
- Auditing for MFA enrollment changes, particularly for administrative or high-value accounts.
- Reviewing authentication token signing certificate usage and validity.
- Implementing robust logging aggregation and monitoring resilience against disabling native logging mechanisms.