Kremlin goons caught abusing ISPs to spy on Moscow-based diplomats, Microsoft says
ID: e7ddb43d-c6cc-5e4a-a584-1a1e15801f0d
STIX ID: report--e7ddb43d-c6cc-5e4a-a584-1a1e15801f0d
Feed Name: The Register (Security)
Microsoft warns that Kremlin-backed APT group Secret Blizzard has been operating since at least 2024 with ISP-level adversary-in-the-middle capabilities in Moscow to intercept embassy traffic and push ApolloShadow malware via captive-portal redirects and fake certificate prompts, enabling TLS/SSL stripping, privilege escalation, and persistent local admin access; victims are advised to route traffic through trusted encrypted tunnels or VPNs whose infrastructure is not controlled by the local ISPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
