<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Microsoft: Russian malware hijacks ADFS to log in as anyone in Windows in Threats</title>
    <link>https://community.isc2.org/t5/Threats/Microsoft-Russian-malware-hijacks-ADFS-to-log-in-as-anyone-in/m-p/52807#M630</link>
    <description>&lt;P&gt;Saw that.&amp;nbsp; "&lt;SPAN&gt;replaces a legitimate DLL used by ADFS with a malicious version" is the bit I can not get past.&amp;nbsp; If the bad actor has gained the necessary permissions to replace a DLL, it seems like we have already reached "game over".&amp;nbsp; Does not really matter what they do after that.&amp;nbsp; The machine is compromised and all data processed by it needs to be presumed disclosed.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 30 Aug 2022 14:32:38 GMT</pubDate>
    <dc:creator>denbesten</dc:creator>
    <dc:date>2022-08-30T14:32:38Z</dc:date>
    <item>
      <title>Microsoft: Russian malware hijacks ADFS to log in as anyone in Windows</title>
      <link>https://community.isc2.org/t5/Threats/Microsoft-Russian-malware-hijacks-ADFS-to-log-in-as-anyone-in/m-p/52785#M629</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Microsoft has discovered a new malware used by the Russian hacker group APT29 (a.k.a. NOBELIUM, Cozy Bear) that enables authentication as anyone in a compromised network.&lt;/P&gt;&lt;P&gt;As a state-sponsored cyberespionage actor, APT29 employs the new capability to hide their presence on the networks of their targets, typically government and critical organizations across Europe, the U.S., and Asia."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.bleepingcomputer.com/news/security/microsoft-russian-malware-hijacks-adfs-to-log-in-as-anyone-in-windows/" target="_blank"&gt;https://www.bleepingcomputer.com/news/security/microsoft-russian-malware-hijacks-adfs-to-log-in-as-anyone-in-windows/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;An interesting read on this attack.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 10:17:36 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Microsoft-Russian-malware-hijacks-ADFS-to-log-in-as-anyone-in/m-p/52785#M629</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-10-09T10:17:36Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft: Russian malware hijacks ADFS to log in as anyone in Windows</title>
      <link>https://community.isc2.org/t5/Threats/Microsoft-Russian-malware-hijacks-ADFS-to-log-in-as-anyone-in/m-p/52807#M630</link>
      <description>&lt;P&gt;Saw that.&amp;nbsp; "&lt;SPAN&gt;replaces a legitimate DLL used by ADFS with a malicious version" is the bit I can not get past.&amp;nbsp; If the bad actor has gained the necessary permissions to replace a DLL, it seems like we have already reached "game over".&amp;nbsp; Does not really matter what they do after that.&amp;nbsp; The machine is compromised and all data processed by it needs to be presumed disclosed.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2022 14:32:38 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Microsoft-Russian-malware-hijacks-ADFS-to-log-in-as-anyone-in/m-p/52807#M630</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2022-08-30T14:32:38Z</dc:date>
    </item>
  </channel>
</rss>

