Microsoft: Russian hackers use ISP access to hack embassies in AiTM attacks
ID: 1725313a-dbfa-5396-b717-0a9c2bdbc038
STIX ID: report--1725313a-dbfa-5396-b717-0a9c2bdbc038
Feed Name: Bleeping Computer
Threat Score
Microsoft attributes an ongoing (since at least 2024) ISP-level adversary-in-the-middle espionage campaign in Moscow to Secret Blizzard (Turla), reporting that the group redirects diplomatic targets to captive portals and deploys ApolloShadow malware disguised as a Kaspersky update that installs a trusted root certificate, enabling persistent interception and credential/traffic spoofing against foreign embassies and sensitive organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
