Malware
ApolloShadow
According to Microsoft, ApolloShadow has the capability to install a trusted root certificate to trick devices into trusting malicious actor-controlled sites, enabling Secret Blizzard to maintain pers
ApolloShadow is a Windows malware family operated by Turla.
Background
Microsoft notes that ApolloShadow can plant a trusted root certificate so that affected devices treat sites controlled by the threat actor as legitimate, allowing Secret Blizzard to keep a foothold on diplomatic systems, most likely for espionage purposes. The malware featured in a campaign in which Secret Blizzard went after embassies in Moscow from an adversary-in-the-middle (AiTM) position.
Source: Malpedia (Fraunhofer FKIE).