Close Menu
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On

Ninja Gaiden 4 Cover Story, Voidbreaker, And Metal Gear 3DS (Feat. Mike Drucker) | The Game Informer Show

31 August 2025

Gear News of the Week: Apple’s iPhone Event Gets a Date, and Plaud Upgrades Its AI Note-Taker

30 August 2025

Security News This Week: DOGE Put Everyone’s Social Security Data at Risk, Whistleblower Claims

30 August 2025
Facebook X (Twitter) Instagram
Just In
  • Ninja Gaiden 4 Cover Story, Voidbreaker, And Metal Gear 3DS (Feat. Mike Drucker) | The Game Informer Show
  • Gear News of the Week: Apple’s iPhone Event Gets a Date, and Plaud Upgrades Its AI Note-Taker
  • Security News This Week: DOGE Put Everyone’s Social Security Data at Risk, Whistleblower Claims
  • What to Look for When Buying a Sleeping Mask
  • Antarctica Is Changing Rapidly. The Consequences Could Be Dire
  • Review: Ride1Up TrailRush Electric Mountain Bike
  • Extreme Heat Makes Your Body Age Faster
  • Scammers Will Try to Trick You Into Filling Out Google Forms. Don’t Fall for It
Facebook X (Twitter) Instagram Pinterest Vimeo
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release
Subscribe
Best in TechnologyBest in Technology
Home » The Kremlin’s Most Devious Hacking Group Is Using Russian ISPs to Plant Spyware
News

The Kremlin’s Most Devious Hacking Group Is Using Russian ISPs to Plant Spyware

News RoomBy News Room31 July 20253 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email

The Russian state hacker group known as Turla has carried out some of the most innovative hacking feats in the history of cyberespionage, hiding their malware’s communications in satellite connections or hijacking other hackers’ operations to cloak their own data extraction. When they’re operating on their home turf, however, it turns out they’ve tried an equally remarkable, if more straightforward, approach: They appear to have used their control of Russia’s internet service providers to directly plant spyware on the computers of their targets in Moscow.

Microsoft’s security research team focused on hacking threats today published a report detailing an insidious new spy technique used by Turla, which is believed to be part of the Kremlin’s FSB intelligence agency. The group, which is also known as Snake, Venomous Bear, or Microsoft’s own name, Secret Blizzard, appears to have used its state-sanctioned access to Russian ISPs to meddle with internet traffic and trick victims working in foreign embassies operating in Moscow into installing the group’s malicious software on their PCs. That spyware then disabled encryption on those targets’ machines so that data they transmitted across the internet remained unencrypted, leaving their communications and credentials like usernames and passwords entirely vulnerable to surveillance by those same ISPs—and any state surveillance agency with which they cooperate.

Sherrod DeGrippo, Microsoft’s director of threat intelligence strategy, says the technique represents a rare blend of targeted hacking for espionage and governments’ older, more passive approach to mass surveillance, in which spy agencies collect and sift through the data of ISPs and telecoms to surveil targets. “This blurs the boundary between passive surveillance and actual intrusion,” DeGrippo says.

For this particular group of FSB hackers, DeGrippo adds, it also suggests a powerful new weapon in their arsenal for targeting anyone within Russia’s borders. “It potentially shows how they think of Russia-based telecom infrastructure as part of their toolkit,” she says.

According to Microsoft’s researchers, Turla’s technique exploits a certain web request browsers make when they encounter a “captive portal,” the windows that are most commonly used to gate-keep internet access in settings like airports, airplanes, or cafes, but also inside some companies and government agencies. In Windows, those captive portals reach out to a certain Microsoft website to check that the user’s computer is in fact online. (It’s not clear whether the captive portals used to hack Turla’s victims were in fact legitimate ones routinely used by the target embassies or ones that Turla somehow imposed on users as part of its hacking technique.)

By taking advantage of its control of the ISPs that connect certain foreign embassy staffers to the internet, Turla was able to redirect targets so that they saw an error message that prompted them to download an update to their browser’s cryptographic certificates before they could access the web. When an unsuspecting user agreed, they instead installed a piece of malware that Microsoft calls ApolloShadow, which is disguised—somewhat inexplicably—as a Kaspersky security update.

That ApolloShadow malware would then essentially disable the browser’s encryption, silently stripping away cryptographic protections for all web data the computer transmits and receives. That relatively simple certificate tampering was likely intended to be harder to detect than a full-featured piece of spyware, DeGrippo says, while achieving the same result.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleQualcomm Said to be Developing Another High-End Chipset; Could Offer Snapdragon 8 Elite-Level Performance
Next Article Time Flies Review – A Short-lived Buzz

Related Articles

News

Gear News of the Week: Apple’s iPhone Event Gets a Date, and Plaud Upgrades Its AI Note-Taker

30 August 2025
News

Security News This Week: DOGE Put Everyone’s Social Security Data at Risk, Whistleblower Claims

30 August 2025
News

What to Look for When Buying a Sleeping Mask

30 August 2025
News

Antarctica Is Changing Rapidly. The Consequences Could Be Dire

30 August 2025
News

Review: Ride1Up TrailRush Electric Mountain Bike

30 August 2025
News

Extreme Heat Makes Your Body Age Faster

30 August 2025
Demo
Top Articles

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024105 Views

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202495 Views

5 laptops to buy instead of the M4 MacBook Pro

17 November 202490 Views

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Latest News
News

Review: Ride1Up TrailRush Electric Mountain Bike

News Room30 August 2025
News

Extreme Heat Makes Your Body Age Faster

News Room30 August 2025
News

Scammers Will Try to Trick You Into Filling Out Google Forms. Don’t Fall for It

News Room30 August 2025
Most Popular

The Spectacular Burnout of a Solar Panel Salesman

13 January 2025129 Views

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024105 Views

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202495 Views
Our Picks

What to Look for When Buying a Sleeping Mask

30 August 2025

Antarctica Is Changing Rapidly. The Consequences Could Be Dire

30 August 2025

Review: Ride1Up TrailRush Electric Mountain Bike

30 August 2025

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us
© 2025 Best in Technology. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.