01:10 PM EDT, 07/31/2025 (MT Newswires) -- Microsoft's ( MSFT ) threat intelligence platform said Thursday that it uncovered a cyberespionage campaign by a Russian state actor that has been targeting embassies located in Moscow.
The Russian state actor, referred to as Secret Blizzard, is using an adversary-in-the-middle position to deploy a malware called ApolloShadow on devices, the company said in a blog post.
While this cyberespionage campaign has been ongoing since 2024, Microsoft ( MSFT ) said it can now confirm that Secret Blizzard has the capability to do so at the internet service provider level, meaning that diplomats using local internet or telecommunication services are highly likely to be on Secret Blizzard's radar.
ApolloShadow works by installing a trusted root certificate to trick devices into trusting malicious actor-controlled sites, thus enabling Secret Blizzard to maintain its presence on diplomatic devices to extract information, the company said.
Price: 535.55, Change: +22.31, Percent Change: +4.35