logo

Microsoft: Russian hackers use ISP access to hack embassies in AiTM attacks

ID: 1725313a-dbfa-5396-b717-0a9c2bdbc038

STIX ID: report--1725313a-dbfa-5396-b717-0a9c2bdbc038

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-07-31

Date Updated: 2026-07-17

Author: Sergiu Gatlan

...
...

Microsoft attributes an ongoing (since at least 2024) ISP-level adversary-in-the-middle espionage campaign in Moscow to Secret Blizzard (Turla), reporting that the group redirects diplomatic targets to captive portals and deploys ApolloShadow malware disguised as a Kaspersky update that installs a trusted root certificate, enabling persistent interception and credential/traffic spoofing against foreign embassies and sensitive organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.