{"id":5160,"date":"2025-08-01T20:43:28","date_gmt":"2025-08-01T20:43:28","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=5160"},"modified":"2025-08-01T20:43:28","modified_gmt":"2025-08-01T20:43:28","slug":"microsoft-catches-russian-hackers-focusing-on-overseas-embassies","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=5160","title":{"rendered":"Microsoft catches Russian hackers focusing on overseas embassies"},"content":{"rendered":"<p> <br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/12\/GettyImages-1327354395-1152x648.jpg\" \/><\/p>\n<p>Russian-state hackers are focusing on overseas embassies in Moscow with customized malware that will get put in utilizing adversary-in-the-middle assaults that function on the ISP degree, Microsoft warned Thursday.<\/p>\n<p>The marketing campaign has been ongoing since final yr. It leverages ISPs in that nation, that are obligated to work on behalf of the Russian authorities. With the power to manage the ISP community, the risk group\u2014which Microsoft tracks beneath the title Secret Blizzard\u2014positions itself between a focused embassy and the tip factors they connect with, a type of assault referred to as an <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/techniques\/T1557\/\">adversary within the center<\/a>, or AitM. The place permits Secret Blizzard to ship targets to malicious web sites that look like identified and trusted.<\/p>\n<h2>Goal: Set up ApolloShadow<\/h2>\n<p>\u201cWhereas we beforehand assessed with low confidence that the actor conducts cyberespionage actions inside Russian borders towards overseas and home entities, that is the primary time we are able to verify that they&#8217;ve the aptitude to take action on the Web Service Supplier (ISP) degree,\u201d members of the Microsoft Menace Intelligence group <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/07\/31\/frozen-in-transit-secret-blizzards-aitm-campaign-against-diplomats\/\">wrote<\/a>. \u201cWhich means that diplomatic personnel utilizing native ISP or telecommunications companies in Russia are extremely probably targets of Secret Blizzard\u2019s AiTM place inside these companies.\u201d<\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/arstechnica.com\/information-technology\/2025\/07\/microsoft-catches-russian-hackers-targeting-foreign-embassies\/\">Learn full article<\/a><\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/arstechnica.com\/information-technology\/2025\/07\/microsoft-catches-russian-hackers-targeting-foreign-embassies\/#comments\">Feedback<\/a><\/p>\n\n","protected":false},"excerpt":{"rendered":"<p>Russian-state hackers are focusing on overseas embassies in Moscow with customized malware that will get put in utilizing adversary-in-the-middle assaults that function on the ISP degree, Microsoft warned Thursday. The marketing campaign has been ongoing since final yr. It leverages ISPs in that nation, that are obligated to work on behalf of the Russian authorities. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":5162,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[54],"tags":[4420,4421,2042,554,618,538,854],"class_list":["post-5160","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech-news","tag-catches","tag-embassies","tag-foreign","tag-hackers","tag-microsoft","tag-russian","tag-targeting"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/5160","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5160"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/5160\/revisions"}],"predecessor-version":[{"id":5161,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/5160\/revisions\/5161"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/5162"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5160"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5160"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5160"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-09 21:25:01 UTC -->