• News/
  • https://www.bleepingcomputer.com/news/security/microsoft-russian-hackers-use-isp-access-to-hack-embassies-in-aitm-attacks/

Microsoft: Russian hackers use ISP access to hack embassies in AiTM attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Jul 31, 2025
·
Updated

Microsoft warns that a cyber-espionage group linked to Russia's Federal Security Service (FSB) is targeting diplomatic missions in Moscow using local internet service providers. The hacking group tracked by Microsoft as Secret Blizzard (also known as Turla, Waterbug, and Venomous Bear) has been observed exploiting its adversary-in-the-middle (AiTM) position at the internet service provider (ISP) level to infect the systems of diplomatic missions with custom ApolloShadow malware. To do this, they redirect targets to captive portals, tricking them into downloading and executing a malware payload disguised as a Kaspersky antivirus update, which installs a trusted root certificate. Once deployed, ApolloShadow helps trick compromised devices into recognizing malicious websites as legitimate, allowing threat actors to maintain long-term access for intelligence gathering after infiltrating diplomatic systems. "This is the first time Microsoft can confirm Secret Blizzard's capability to conduct espionage at the ISP level, meaning diplomatic personnel using local internet providers and telecommunications in Russia are at high risk of being targets of Secret Blizzard's AiTM position within those services," Microsoft said. "This campaign, which has been ongoing since at least 2024, poses a high risk to foreign embassies, diplomatic entities, and other sensitive organizations operating in Moscow, particularly to those entities who rely on local internet providers." While Microsoft first...

Read full article

Affected Software

2 affected components
Microsoft ApolloShadow
Kaspersky antivirus
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a cyber-espionage group linked to Russia's FSB targeting embassies using access to local internet service providers.

2

What security implications are discussed in the article?

The implications include the risk of sensitive diplomatic information being compromised through sophisticated hacking techniques.

3

Which hacking technique is highlighted in the article?

The article highlights Account Theft Mitigation (AiTM) attacks as the method being used by the hackers.

4

What products or software are affected by this security issue?

The affected products include Microsoft ApolloShadow and Kaspersky antivirus.

5

Who is behind the hacking group discussed in the article?

The hacking group is reportedly linked to Russia's Federal Security Service (FSB).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203