Russia-linked APT Secret Blizzard targets foreign embassies in Moscow with ApolloShadow malware
ID: fb762f07-de00-5790-a66b-67f14e059943
STIX ID: report--fb762f07-de00-5790-a66b-67f14e059943
Feed Name: Security Affairs
Threat Score
Microsoft uncovered a Russia-linked APT campaign (Secret Blizzard/Turla) using ISP-level adversary-in-the-middle techniques in Moscow to serve a fake captive portal that installs ApolloShadow malware; the malware prompts elevated privileges to install rogue Kaspersky-like root certificates, weaken host defenses, create hidden admin accounts, intercept traffic, and harvest credentials from diplomatic targets, and Microsoft published related IoCs and TTP details.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
