logo

Russian State Hackers Spy on Moscow Embassies via ISP-Level AiTM Attacks

ID: cb33cb4b-8658-5b72-b537-8a11cac9643d

STIX ID: report--cb33cb4b-8658-5b72-b537-8a11cac9643d

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2025-08-01

Date Updated: 2026-04-22

Author: Ddos

...
...

Microsoft uncovered a sophisticated Russian state-sponsored AiTM operation (Secret Blizzard) targeting diplomatic devices in Moscow using custom malware called ApolloShadow; the malware installs malicious root certificates, intercepts and decrypts traffic, exfiltrates credentials, creates a persistent administrative account (UpdatusUser), and leverages ISP-level redirection and spoofed domains to deliver and control payloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.