Russian Cyberspies Target Diplomatic Devices: Microsoft’s Cyber-Espionage Alert

Russian cyberspies are using local ISPs to target foreign embassies in Moscow, intercepting sensitive data through an adversary-in-the-middle attack, warns Microsoft. Dubbed Secret Blizzard, the Kremlin-backed group deploys custom malware to snoop on diplomats’ devices. So, if you’re in Moscow, maybe avoid that Wi-Fi network named “Definitely_Real_Internet.”

Pro Dashboard

Hot Take:

Looks like Russian cyberspies have decided to play peek-a-boo with embassy communications in Moscow. Instead of using traditional spy gadgets like invisible ink or trench coats, they’re opting for the high-tech version of hiding behind the bushes: hijacking local ISPs! Who knew being a diplomat could make you the star of a cyber-espionage thriller?

Key Points:

  • Russian cyberspies are exploiting local ISPs to target foreign embassies in Moscow.
  • The campaign is linked to the Kremlin-backed group Secret Blizzard, known for cyber-espionage.
  • Secret Blizzard employs an adversary-in-the-middle (AiTM) technique to intercept communications.
  • The attack involves redirecting devices to a captive portal and deploying ApolloShadow malware.
  • Microsoft advises using encrypted tunnels or VPNs to avoid ISP-level interception.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?