Microsoft warns that a cyber-espionage group linked to Russia's Federal Security Service (FSB) is targeting diplomatic missions in Moscow using local internet service providers. The hacking group tracked by Microsoft as Secret Blizzard (also known as Turla, Waterbug, and Venomous Bear) has been observed exploiting its adversary-in-the-middle (AiTM) position at the internet service provider (ISP) level to infect the systems of diplomatic missions with custom ApolloShadow malware. To do this, they redirect targets to captive portals, tricking them into downloading and executing a malware payload disguised as a Kaspersky antivirus update, which installs a trusted root certificate. Once deployed, ApolloShadow helps trick compromised devices into recognizing malicious websites as legitimate, allowing threat actors to maintain long-term access for intelligence gathering after infiltrating diplomatic systems. "This is the first time Microsoft can confirm Secret Blizzard's capability to conduct espionage at the ISP level, meaning diplomatic personnel using local internet providers and telecommunications in Russia are at high risk of being targets of Secret Blizzard's AiTM position within those services," Microsoft said. "This campaign, which has been ongoing since at least 2024, poses a high risk to foreign embassies, diplomatic entities, and other sensitive organizations operating in Moscow, particularly to those entities who rely on local internet providers." While Microsoft first...
Microsoft: Russian hackers use ISP access to hack embassies in AiTM attacks
BleepingComputer
·Sergiu Gatlan
·Published Jul 31, 2025
·Updated
Affected Software
2 affected components
Microsoft ApolloShadow
Kaspersky antivirus
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a cyber-espionage group linked to Russia's FSB targeting embassies using access to local internet service providers.
2
What security implications are discussed in the article?
The implications include the risk of sensitive diplomatic information being compromised through sophisticated hacking techniques.
3
Which hacking technique is highlighted in the article?
The article highlights Account Theft Mitigation (AiTM) attacks as the method being used by the hackers.
4
What products or software are affected by this security issue?
The affected products include Microsoft ApolloShadow and Kaspersky antivirus.
5
Who is behind the hacking group discussed in the article?
The hacking group is reportedly linked to Russia's Federal Security Service (FSB).