Secret Blizzard Deploys Malware in ISP-Level AitM Attacks on Moscow Embassies

An adversary-in-the-middle (AitM) attack at the Internet Service Provider (ISP) level, utilizing a custom malware called ApolloShadow, has been used to launch a new cyber espionage campaign against foreign embassies in Moscow by the Russian nation-state threat actor known as Secret Blizzard.

According to a report shared with The Hacker News, the Microsoft Threat Intelligence team stated that ApolloShadow can install a trusted root certificate to fool devices into believing malicious actor-controlled websites. This allows Secret Blizzard to remain persistent on diplomatic devices, most likely for intelligence gathering.

According to assessments, the campaign has been going on since at least 2024 and poses a security risk to diplomatic staff who depend on Russian telecommunications services or local ISPs.

Under the aliases Blue Python, Iron Hunter, Pensive Ursa, Snake, SUMMIT, Uroburos, Turla, Venomous Bear, and Waterbug, the larger cybersecurity community also keeps tabs on Secret Blizzard read more about Secret Blizzard Deploys Malware in ISP-Level AitM Attacks on Moscow Embassies.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *