Notorious Russian Hacking Group Has A New Trick to Maintain Persistence
Microsoft says the same threat actors that compromised SolarWinds Orion are leveraging AD FS to maintain access.
Microsoft says it has uncovered a tactic used by Russia-aligned threat actors that is used to maintain persistence access to compromised environments after leveraging an Active Directory Federation Services (AD FS) server. In a lengthy blog post, Microsoft details how NOBELIUM—the codename attached to the same threat group that leveraged the SolarWinds Orion platform and […]