MagicWeb is a highly targeted post-compromise AD FS backdoor used by NOBELIUM, now tracked by Microsoft as Midnight Blizzard, a Russian SVR-linked espionage actor also known as APT29/Cozy Bear. Microsoft described it as a persistence capability deployed after the actor obtained highly privileged credentials and administrative access to an Active Directory Federation Services (AD FS) server; Microsoft explicitly stated the incident was not a supply-chain attack. MagicWeb consists of a malicious, unsigned backdoored version of Microsoft.IdentityServer.Diagnostics.dll. The actor modifies C:\Windows\AD FS\Microsoft.IdentityServer.Servicehost.exe.config to alter the public token so AD FS loads the attacker-controlled DLL from the Global Assembly Cache instead of the legitimate Microsoft-signed library. Once loaded, the malware intercepts and manipulates claims in tokens generated by AD FS, enabling the actor to authenticate as arbitrary users and bypass AD FS role, device, and network policies, including MFA. Microsoft reported that MagicWeb abuses hardcoded non-standard Enhanced Key Usage OIDs in user authentication certificates for specified UPNs to trigger claim injection and certificate-validation bypass behavior. MagicWeb is associated with NOBELIUM/Midnight Blizzard operations targeting government organizations, NGOs, IGOs, and think tanks across the United States, Europe, and Central Asia, and is referenced alongside the actor’s earlier AD FS malware FoggyWeb. Known detection-related indicators mentioned in the content include the modified AD FS service host configuration file, non-default PublicKeyToken values where the default is 31bf3856ad364e35, unsigned or untrusted Microsoft.IdentityServer.*.dll files in AD FS or GAC locations, Microsoft Defender Antivirus detection as Trojan:MSIL/MagicWeb.A!dha, and Microsoft Defender for Endpoint alerting as 'ADFS persistent backdoor detected'.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Microsoft reference: 'MagicWeb: NOBELIUM’s post-compromise trick to authenticate as anyone.'
11 distinct techniques documented for this family, organized by ATT&CK tactic.
NOBELIUM was able to deploy MagicWeb by first gaining access to highly privileged credentials and moving laterally to gain administrative privileges to an AD FS system.
Microsoft security researchers have discovered a post-compromise capability we’re calling MagicWeb, which is used by a threat actor we track as NOBELIUM to maintain persistent access to compromised environments.
APT29 routinely cleans up by removing their tools and backdoors once legitimate remote access is secured, often deploying a web shell on Microsoft Exchange servers after a successful compromise.
The interception and manipulation of claims by MagicWeb enables the actor to generate tokens that allow the adversary to bypass AD FS policies (role policies, device policies, and network policies) and sign in as any user with any claims, including multifactor authentication (MFA).
NOBELIUM was able to deploy MagicWeb by first gaining access to highly privileged credentials and moving laterally to gain administrative privileges to an AD FS system.
After gaining administrative access to an AD FS server via elevation of privilege and lateral movement, the loading of NOBELIUM’s malicious Microsoft.IdentityServer.Diagnostics.dll into the AD FS process is possible by editing C:\Windows\AD FS\Microsoft.IdentityServer.Servicehost.exe.config to specify a different public token...
The interception and manipulation of claims by MagicWeb enables the actor to generate tokens that allow the adversary to bypass AD FS policies (role policies, device policies, and network policies) and sign in as any user with any claims, including multifactor authentication (MFA).
The interception and manipulation of claims by MagicWeb enables the actor to generate tokens that allow the adversary to bypass AD FS policies (role policies, device policies, and network policies) and sign in as any user with any claims, including multifactor authentication (MFA).
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Their toolkit includes ... LiteDuke, MagicWeb, meek, Mimikatz...
AD FS malware used by Midnight Blizzard.
A post-compromise malicious DLL backdoor targeting AD FS servers. It manipulates claims in authentication tokens, bypasses AD FS policies including MFA, and enables covert persistent access by allowing sign-in as any user with arbitrary claims.
Post-compromise malware or capability used to manipulate authentication flows and enable attacker impersonation in compromised environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.