Secret Blizzard Deploys Malware in ISP-Level AitM Attacks on Moscow Embassies
An adversary-in-the-middle (AitM) attack at the Internet Service Provider (ISP) level, utilizing a custom malware called ApolloShadow, has been used to launch a new cyber espionage campaign against foreign embassies in Moscow by the Russian nation-state threat actor known as Secret Blizzard.
According to a report shared with The Hacker News, the Microsoft Threat Intelligence team stated that ApolloShadow can install a trusted root certificate to fool devices into believing malicious actor-controlled websites. This allows Secret Blizzard to remain persistent on diplomatic devices, most likely for intelligence gathering.
According to assessments, the campaign has been going on since at least 2024 and poses a security risk to diplomatic staff who depend on Russian telecommunications se...

