Russian State Hackers Spy on Moscow Embassies via ISP-Level AiTM Attacks
ID: cb33cb4b-8658-5b72-b537-8a11cac9643d
STIX ID: report--cb33cb4b-8658-5b72-b537-8a11cac9643d
Feed Name: securityonline.info
Threat Score
Microsoft uncovered a sophisticated Russian state-sponsored AiTM operation (Secret Blizzard) targeting diplomatic devices in Moscow using custom malware called ApolloShadow; the malware installs malicious root certificates, intercepts and decrypts traffic, exfiltrates credentials, creates a persistent administrative account (UpdatusUser), and leverages ISP-level redirection and spoofed domains to deliver and control payloads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
