ApolloShadow is a custom Windows backdoor used by the Russian state-linked Secret Blizzard espionage group, also tracked as Turla, against foreign embassies and diplomatic personnel in Moscow. The operation has been active since at least 2024 and uses an ISP-level adversary-in-the-middle position, likely enabled by Russian lawful-intercept capabilities, to redirect Windows connectivity checks through a captive-portal flow. Victims are socially engineered into executing malware masquerading as Kaspersky-related certificate software.
ApolloShadow installs attacker-controlled trusted root certificates, enabling interception or stripping of TLS protections and causing victim systems to trust malicious sites and traffic. It can collect host network information and transmit it to actor-controlled infrastructure. When elevated privileges are available or obtained through a deceptive UAC prompt, it changes network profiles to private, relaxes firewall settings to permit network discovery and file sharing, and creates a persistent local administrative account. These changes facilitate sustained espionage access and may reduce barriers to lateral movement within compromised diplomatic networks. ApolloShadow also obfuscates strings and scripts to hinder detection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Victims are tricked into installing a malicious tool, ApolloShadow which enables TLS interception, credential theft, and persistent espionage when installed.
"The attack starts with a captive portal redirect that tricks targets into downloading ApolloShadow malware disguised as a Kaspersky certificate installer."
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Secret Blizzard intercepts the Windows connectivity check request and redirects the system to a malicious domain, prompting the download and execution of ApolloShadow.
Secret Blizzard is gaining initial access to embassy employee devices by redirecting them to a malicious domain that displays a certificate validation error... The error prompts and tricks embassy employees into downloading root certificates falsely branded as Kaspersky Anti-Virus software, which deploy ApolloShadow malware.
ApolloShadow obfuscates critical strings and scripts to evade detection.
Finally, ApolloShadow creates an administrative user with the username UpdatusUser and a hardcoded password, set to never expire, on the compromised system using the Windows API NetUserAdd. The malware now has persistent access to the infected host via the newly created local admin user.
Annex B maps the campaign's defense-evasion behavior to Modify Registry.
The final step is to create an administrative user with the username UpdatusUser and a never-expiring hardcoded password on the infected system, using the Windows API NetUserAdd.
Finally, ApolloShadow creates an administrative user with the username UpdatusUser and a hardcoded password, set to never expire, on the compromised system using the Windows API NetUserAdd. The malware now has persistent access to the infected host via the newly created local admin user.
[ApolloShadow] obfuscates critical strings and scripts to evade detection.
Annex B maps the campaign's defense-evasion behavior to Modify Registry.
It presents a User Access Control (UAC) prompt to install root certificates, disguised as a Kaspersky installer (CertificateDB.exe), enabling TLS interception.
"We assess this allows for TLS/SSL stripping from the Secret Blizzard AiTM position, rendering the majority of the target's browsing in clear text including the delivery of certain tokens and credentials," Microsoft wrote.
Intrusions linked to this politically motivated espionage campaign allow Secret Blizzard to view the majority of the target’s browsing in plain text, including certain tokens and credentials, researchers said in the report.
It’s a shift, or a kind of movement, toward the evolution of simply watching traffic to actively modifying network traffic in order to get into those targeted systems.
Victims are tricked into installing ... ApolloShadow which enables TLS interception, credential theft, and persistent espionage.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware/tool used in Secret Blizzard adversary-in-the-middle activity targeting diplomats.
Custom malware delivered in ISP-level adversary-in-the-middle attacks; capable of installing a trusted root certificate (per summary).
Custom cyberespionage malware used in ISP-level adversary-in-the-middle operations; installs a rogue trusted root certificate to intercept/manipulate encrypted web traffic, facilitates credential theft and persistent surveillance, attempts privilege escalation, creates a new admin user for backdoor access, and weakens network/browser security settings.
Malware deployed via adversary-in-the-middle attacks at the ISP level, used for intelligence collection from diplomats' devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.