logo

Kremlin goons caught abusing ISPs to spy on Moscow-based diplomats, Microsoft says

ID: e7ddb43d-c6cc-5e4a-a584-1a1e15801f0d

STIX ID: report--e7ddb43d-c6cc-5e4a-a584-1a1e15801f0d

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2025-07-31

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Microsoft warns that Kremlin-backed APT group Secret Blizzard has been operating since at least 2024 with ISP-level adversary-in-the-middle capabilities in Moscow to intercept embassy traffic and push ApolloShadow malware via captive-portal redirects and fake certificate prompts, enabling TLS/SSL stripping, privilege escalation, and persistent local admin access; victims are advised to route traffic through trusted encrypted tunnels or VPNs whose infrastructure is not controlled by the local ISPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.