logo

Russia-linked APT Secret Blizzard targets foreign embassies in Moscow with ApolloShadow malware

ID: fb762f07-de00-5790-a66b-67f14e059943

STIX ID: report--fb762f07-de00-5790-a66b-67f14e059943

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2025-07-31

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Microsoft uncovered a Russia-linked APT campaign (Secret Blizzard/Turla) using ISP-level adversary-in-the-middle techniques in Moscow to serve a fake captive portal that installs ApolloShadow malware; the malware prompts elevated privileges to install rogue Kaspersky-like root certificates, weaken host defenses, create hidden admin accounts, intercept traffic, and harvest credentials from diplomatic targets, and Microsoft published related IoCs and TTP details.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.