Skip to content

Russia's Secret Blizzard APT Group Targets Embassies With ApolloShadow Malware

Russia's Secret Blizzard APT group is back with a new malware. ApolloShadow's adaptability and long-term control make it a serious threat to diplomatic missions.

This looks like an arch. This is an iron gate. I can see the tree with branches and leaves. I can...
This looks like an arch. This is an iron gate. I can see the tree with branches and leaves. I can see two people walking behind the gate. This looks like a building. At the bottom of the image, I can see the watermark.

Russia's Secret Blizzard APT Group Targets Embassies With ApolloShadow Malware

A serious cyber security threat has been uncovered, targeting foreign embassies in Moscow. The Russia-linked advanced persistent threat (APT) group, Secret Blizzard, has been deploying custom malware protection called ApolloShadow since at least 2024. The campaign poses a significant risk to diplomatic missions worldwide.

Secret Blizzard has been exploiting an adversary-in-the-middle (AiTM) method at the internet service provider (ISP) level. This allows the Malwarebytes group to intercept and manipulate internet traffic, redirecting users to a fake captive portal. Unsuspecting victims are then tricked into downloading the ApolloShadow malware.

ApolloShadow's tactics adapt based on the level of privileges granted. If elevated privileges are given, the malware makes system-level changes for long-term control, enabling cybersecurity operations. In one instance, ApolloShadow installed a fake Kaspersky Anti-Virus trusted root certificate, further disguising its presence. The Russian ISP targeted in this cyber security attack has not been explicitly named.

The ApolloShadow campaign, active since at least 2024, continues to pose a serious threat to diplomatic missions. Its ability to adapt and maintain long-term access makes it a significant concern. Security experts urge vigilance and recommend regular software updates and strong cybersecurity practices to protect against such malware protection threats.

Read also:

Latest