logo

Secret Blizzard Group’s ApolloShadow Malware Install Root Certificates on Devices to Trust Malicious Sites

ID: e42632c8-70b2-5625-8cd8-4e858f431f47

STIX ID: report--e42632c8-70b2-5625-8cd8-4e858f431f47

Feed Name: cybersecurityNews.com

Threat Score
92/100

Date Published: 2025-08-01

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Microsoft analysts uncovered a sophisticated Secret Blizzard AiTM campaign targeting foreign embassies in Moscow using ApolloShadow malware deployed via ISP-level interception. ApolloShadow installs malicious root and CA certificates (using certutil), modifies Firefox to trust those certificates, creates a persistent administrative account, and alters network profiles to enable interception and potential lateral movement, representing a high-risk nation-state espionage operation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.