Skip to content

Malware

ApolloShadow

According to Microsoft, ApolloShadow has the capability to install a trusted root certificate to trick devices into trusting malicious actor-controlled sites, enabling Secret Blizzard to maintain pers

ApolloShadow is a Windows malware family operated by Turla.

Background

Microsoft notes that ApolloShadow can plant a trusted root certificate so that affected devices treat sites controlled by the threat actor as legitimate, allowing Secret Blizzard to keep a foothold on diplomatic systems, most likely for espionage purposes. The malware featured in a campaign in which Secret Blizzard went after embassies in Moscow from an adversary-in-the-middle (AiTM) position.


Source: Malpedia (Fraunhofer FKIE).