Today we are releasing an in-depth analysis of a #NOBELIUM post-exploitation backdoor that Microsoft Threat Intelligence Center (MSTIC) refers to as #FoggyWeb, a passive & highly targeted backdoor capable of remotely exfiltrating sensitive info from a compromised AD FS server.
New blog: In-depth analysis of newly detected NOBELIUM malware: a post-exploitation backdoor that Microsoft refers to as FoggyWeb. NOBELIUM uses FoggyWeb to remotely exfiltrate data from compromised AD FS servers. Get IOCs, protection info, and guidance: https://t.co/miVx4gAOxp
The Gentlemen ransomware is a ransomware-as-a-service (RaaS) threat that is distinguished by its ability to pair its strong per-file encryption with an aggressive self-propagation capability designed to enable broad network compromise. Another quality blog by #MIRAGE and Microsoft Threat Intelligence.
The Gentlemen ransomware: Dissecting a self-propagating Go encryptor https://t.co/shcE55s61q
#GentlemenRansomware
Another quality technical blog from #MIRAGE, this time on Secret Blizzard’s beloved #Kazuar malware. This blog is an in-depth analysis of Kazuar’s progression from a single, monolithic framework into a modular bot ecosystem composed of three distinct module types, each with clearly defined roles. Together, these components distribute functionality across the P2P botnet, enabling flexible configuration, lower observability, and broad tasking while minimizing opportunities for detection.
https://t.co/0VzspKN1Wa
Microsoft Threat Intelligence uncovered a macOS‑focused cyber campaign by the North Korean threat actor Sapphire Sleet that relies on social engineering rather than software vulnerabilities.
https://t.co/uAPXe5pqIV
Forest Blizzard, a threat actor linked to the Russian military, has been compromising insecure small-office and home internet equipment like routers to conduct DNS hijacking and adversary-in-the-middle attacks https://t.co/612214XwVg
Join MSTIC‑MIRAGE, MSTIC’s global team of elite malware intelligence, reverse engineering, and security research specialists. Work alongside a world-class team of REs and TI analysts to uncover, analyze, research, track, and disrupt some of the world’s most advanced and consequential cyber threats (US-based candidates with senior-level+ RE experience):
https://t.co/Gf9Hykej7U
New blog post: Shai-Hulud 2.0: Guidance for detecting, investigating, and defending against the supply chain attack. https://t.co/I05I2pYgMi
In defending against threats like Shai-Hulud 2.0, organizations benefit significantly from the layered protection from Microsoft Defender, which provides security coverage from code, to posture management, to runtime. This defense-in-depth approach is especially valuable when facing supply chain-driven attacks that might introduce malicious dependencies that evade traditional vulnerability assessment tools.
In these scenarios, the ability to correlate telemetry across data planes, such as endpoint or container behavior and runtime anomalies, becomes essential. Leveraging these insights enables security teams to rapidly identify compromised devices, flag suspicious packages, and contain the threat before it propagates further.
RIFT Update ⚡
Automate rustc_hashes.json updates with new Linux & Windows scripts! Easier than ever.
👉 https://t.co/ebU50hwvgt
#CyberSec#MalwareResearch#RIFT
Microsoft Incident Response – Detection and Response Team (DART) uncovered SesameOp, a new backdoor that uses the OpenAI Assistants API for C2. DART shared the findings with OpenAI, who identified and disabled an API key and associated account. https://t.co/HlSydzE7Xv
SesameOp uses the OpenAI Assistants API as a storage or relay mechanism to fetch commands, which the malware then decrypts and executes locally. Once the tasks are completed, it sends the results back to OpenAI as a message. To stay under the radar, the backdoor uses compression and encryption.
Microsoft and OpenAI jointly investigated the threat actor’s use of the OpenAI Assistants API. This threat does not represent a vulnerability or misconfiguration, but a way to misuse built-in capabilities of the OpenAI Assistants API, which is being deprecated in August 2026. Microsoft and OpenAI continue to collaborate to better understand and disrupt how threat actors attempt to misuse emerging technologies.
Just dropped: my RECON 2025 talk on Rust library recognition in malware! 🦀
Worth a watch if you're into RE or malware research.
https://t.co/1OzsYkCyTa
#malware#RIFT#microsoft#reverseengineering#rust
Microsoft Threat Intelligence has uncovered a new variant of the XCSSET malware, which is designed to infect Xcode projects, typically used by software developers building Apple or macOS-related applications. https://t.co/EiRNH37RFI
This new XCSSET variant improves browser targeting, clipboard hijacking, and persistence mechanisms. It employs sophisticated encryption and obfuscation techniques, uses run-only compiled AppleScripts for stealth, and expands data exfiltration capabilities.
We shared these findings with Apple and collaborated with GitHub to take down repositories affected by XCSSET. This publication reflects our broader commitment to disrupting attacks and dismantling attacker operations. Alongside our findings, we are sharing actionable detections, recommendations, and best practices to help organizations defend against this threat with confidence.
#PipeMagic is a highly modular backdoor used by the financially motivated threat actor Storm-2460. It masquerades as a legitimate open-source ChatGPT Desktop Application. Microsoft Threat Intelligence encountered PipeMagic as part of research on an attack chain involving the exploitation of CVE-2025-29824, an elevation of privilege vulnerability in Windows Common Log File System (CLFS). PipeMagic is a sophisticated malware framework designed for flexibility and persistence.
Quality blog by MSTIC malware intelligence, research and analysis (MIRAGE) team: https://t.co/SUAkpGLouw
#pipemagic #mstic #mirage #threatintelligence
Microsoft Threat Intelligence has uncovered a cyberespionage campaign by the Russian state actor we track as Secret Blizzard that has been targeting embassies located in Moscow using an adversary-in-the-middle (AiTM) position to deploy their custom #ApolloShadow malware.
https://t.co/n10NihobGX
#ApolloShadow #MSTIC #MIRAGE
🚨 RIFT Update:
We’ve boosted our compiler detection! 🛠️
Now with sharper insights into binaries built using GNU, MinGW, and MSVC toolchains.
More enhancements are on the way—stay tuned! 🔍✨
#ReverseEngineering#MalwareAnalysis#RIFT#malware#msft
https://t.co/ebU50hwvgt
Today, Microsoft Threat Intelligence Center (#MSTIC) is excited to announce the release of #RIFT, a tool designed to assist software/malware analysts automate the identification of attacker-written code within Rust binaries.
Blog: https://t.co/ywgr82vjQF
Tool: https://t.co/zYUnJm3Orq
#RIFT #Rust #MSTIC #MIRAGE @hackingump1
Do you find analyzing Rust binaries/malware tedious and unpleasant? You’re not alone! If you’re attending #REcon this year, our own @hackingump1 will be unveiling #RIFT today at 2PM EST (not at REcon? We got you covered, stay tuned). We have been using RIFT internally for some time and it has truly transformed the way we handle and analyze Rust binaries.
https://t.co/RjyW093DUS
#RIFT #Rust #REon25 #MSTIC #MIRAGE
Do you find analyzing Rust binaries/malware tedious and unpleasant? You’re not alone! If you’re attending #REcon this year, our own @hackingump1 will be unveiling #RIFT today at 2PM EST (not at REcon? We got you covered, stay tuned). We have been using RIFT internally for some time and it has truly transformed the way we handle and analyze Rust binaries.
https://t.co/RjyW093DUS
#RIFT #Rust #REon25 #MSTIC #MIRAGE
Presenting "Unveiling RIFT: Advanced Pattern Matching for Rust Libraries" at RECON Montreal 2025!
Sharing research on discovering Rust dependencies in compiled binaries.
See you there! 🚀
#RECON2025#RustLang#ReverseEngineering