Friday, 1 August, 2025
Microsoft Exposes FSB-backed Malware Campaign Targeting Foreign Embassies in Moscow

Microsoft Threat Intelligence revealed that Russia’s FSB-linked hacking group—known as “Secret Blizzard” or Turla—executed a covert cyber‑espionage campaign against foreign embassies in Moscow beginning in February 2025. The attackers leveraged ISP-level access and Russia’s SORM surveillance infrastructure to redirect diplomats into fake certificate prompts, installing “ApolloShadow” malware disguised as Kaspersky software. The malware stripped browser encryption, exposing credentials & traffic.