ApolloShadow is a custom malware used in a cyberespionage campaign attributed by Microsoft Threat Intelligence to the Russian state-backed group Secret Blizzard, also known as Turla, Venomous Bear, Uroburos, Waterbug, Pensive Ursa, Wraith, and ATG26, and linked in the reporting to Russia’s FSB Center 16. Public reporting states the campaign targeted foreign embassies in Moscow and had been active since at least 2024. The malware was delivered via ISP- or telco-level adversary-in-the-middle operations in which targets were redirected through a captive portal flow and tricked into downloading a fake certificate installer, including Kaspersky-branded lures such as CertificateDB.exe. ApolloShadow installs a rogue or trusted root certificate on the victim system, causing malicious sites and traffic to appear legitimate and enabling interception, manipulation, and in some reporting TLS/SSL stripping of encrypted web traffic. Reported host actions include attempting privilege escalation, presenting a UAC prompt, changing network profiles to private, weakening or modifying firewall settings to enable file sharing and network discovery, and creating a persistent local administrative account named UpdatusUser with a hardcoded non-expiring password using NetUserAdd. Microsoft assessed these changes likely facilitate persistent access and reduce the difficulty of later lateral movement within embassy networks. Reported exposed data includes browsing activity in clear text as well as certain tokens and credentials. High-confidence indicators and artifacts directly mentioned in the content include the filenames CertificateDB.exe and the account name UpdatusUser, as well as abuse of the Windows connectivity check to redirect traffic from msftconnecttest.com/redirect toward actor-controlled infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2025-07-31 ⋅ Microsoft Threat Intelligence Frozen in transit: Secret Blizzard’s AiTM campaign against diplomats ApolloShadow
"The attack starts with a captive portal redirect that tricks targets into downloading ApolloShadow malware disguised as a Kaspersky certificate installer."
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Secret Blizzard is gaining initial access to embassy employee devices by redirecting them to a malicious domain that displays a certificate validation error... The error prompts and tricks embassy employees into downloading root certificates falsely branded as Kaspersky Anti-Virus software, which deploy ApolloShadow malware.
Finally, ApolloShadow creates an administrative user with the username UpdatusUser and a hardcoded password, set to never expire, on the compromised system using the Windows API NetUserAdd. The malware now has persistent access to the infected host via the newly created local admin user.
The final step is to create an administrative user with the username UpdatusUser and a never-expiring hardcoded password on the infected system, using the Windows API NetUserAdd.
Finally, ApolloShadow creates an administrative user with the username UpdatusUser and a hardcoded password, set to never expire, on the compromised system using the Windows API NetUserAdd. The malware now has persistent access to the infected host via the newly created local admin user.
"We assess this allows for TLS/SSL stripping from the Secret Blizzard AiTM position, rendering the majority of the target's browsing in clear text including the delivery of certain tokens and credentials," Microsoft wrote.
Intrusions linked to this politically motivated espionage campaign allow Secret Blizzard to view the majority of the target’s browsing in plain text, including certain tokens and credentials, researchers said in the report.
It’s a shift, or a kind of movement, toward the evolution of simply watching traffic to actively modifying network traffic in order to get into those targeted systems.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware/tool used in Secret Blizzard adversary-in-the-middle activity targeting diplomats.
Custom malware delivered in ISP-level adversary-in-the-middle attacks; capable of installing a trusted root certificate (per summary).
Custom cyberespionage malware used in ISP-level adversary-in-the-middle operations; installs a rogue trusted root certificate to intercept/manipulate encrypted web traffic, facilitates credential theft and persistent surveillance, attempts privilege escalation, creates a new admin user for backdoor access, and weakens network/browser security settings.
Malware deployed via adversary-in-the-middle attacks at the ISP level, used for intelligence collection from diplomats' devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.