Threat Advisories:
🎧 Hive Force Labs: Critical Threats Affecting You This Week - 5 Minute Audio Intelligence Report
👥 Play Count: Loading...

Secret Blizzard Strikes Moscow with ApolloShadow

Amber | Attack Report
Download PDF

The Russian state-sponsored group Secret Blizzard is running a targeted cyber-espionage operation against diplomats in Moscow. By leveraging an adversary-in-the-middle (AiTM) position, likely made possible through cooperation with local internet service providers, they intercept network traffic and redirect victims to a deceptive captive portal. There, targets are tricked into downloading a fake Kaspersky Anti-Virus installer that silently drops ApolloShadow malware. This malware installs a rogue trusted root certificate, allowing the attackers to maintain long-term access and intercept encrypted communications. Secret Blizzard also uses stealthy techniques to map networks, evade defenses, and extract sensitive intelligence without being detected.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox

Cybersecurity Leaders Dinner In Houston

Learn how to reduce your exposure to imminent risk & Network with Industry Peers

Hosted by former CISO, Al Lindseth and Threat Exposure Evangelist, Critt Golden.

Tuesday, October 7th, 2025
6.00 pm to 9.00 pm
Del Friscos Double Eagle Steakhouse, Houston TX