Close Menu
Voxa News

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    The Best Mushroom Gummies on the Market, Lab-Approved (2025)

    September 21, 2025

    Optimo DJ JD Twitch dies after being diagnosed with brain tumour

    September 21, 2025

    Blue Jays clinch MLB playoff berth, still targeting AL East division title and American League’s best record

    September 21, 2025
    Facebook X (Twitter) Instagram
    Voxa News
    Trending
    • The Best Mushroom Gummies on the Market, Lab-Approved (2025)
    • Optimo DJ JD Twitch dies after being diagnosed with brain tumour
    • Blue Jays clinch MLB playoff berth, still targeting AL East division title and American League’s best record
    • News live: Netanyahu warns Albanese to ‘stand by’ after Australia recognises Palestine; Sydney trains to ban some ebikes | Australia news
    • The Guardian view on Wedgwood’s challenges: potteries face an existential crisis | Industrial policy
    • ‘We’re here to help’: how Ofcom is urging porn sites to follow the Online Safety Act | Pornography
    • Margot Robbie, Colin Farrell on Big Bold Beautiful Journey, Original Films
    • Emilia Wickstead Spring 2026 Ready-to-Wear Collection
    Sunday, September 21
    • Home
    • Business
    • Health
    • Lifestyle
    • Politics
    • Science
    • Sports
    • Travel
    • World
    • Entertainment
    • Technology
    Voxa News
    Home»Technology»The Kremlin’s Most Devious Hacking Group Is Using Russian ISPs to Plant Spyware
    Technology

    The Kremlin’s Most Devious Hacking Group Is Using Russian ISPs to Plant Spyware

    By Olivia CarterJuly 31, 2025No Comments3 Mins Read0 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    The Kremlin's Most Devious Hacking Group Is Using Russian ISPs to Plant Spyware
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The Russian state hacker group known as Turla has carried out some of the most innovative hacking feats in the history of cyberespionage, hiding their malware’s communications in satellite connections or hijacking other hackers’ operations to cloak their own data extraction. When they’re operating on their home turf, however, it turns out they’ve tried an equally remarkable, if more straightforward, approach: They appear to have used their control of Russia’s internet service providers to directly plant spyware on the computers of their targets in Moscow.

    Microsoft’s security research team focused on hacking threats today published a report detailing an insidious new spy technique used by Turla, which is believed to be part of the Kremlin’s FSB intelligence agency. The group, which is also known as Snake, Venomous Bear, or Microsoft’s own name, Secret Blizzard, appears to have used its state-sanctioned access to Russian ISPs to meddle with internet traffic and trick victims working in foreign embassies operating in Moscow into installing the group’s malicious software on their PCs. That spyware then disabled encryption on those targets’ machines so that data they transmitted across the internet remained unencrypted, leaving their communications and credentials like usernames and passwords entirely vulnerable to surveillance by those same ISPs—and any state surveillance agency with which they cooperate.

    Sherrod DeGrippo, Microsoft’s director of threat intelligence strategy, says the technique represents a rare blend of targeted hacking for espionage and governments’ older, more passive approach to mass surveillance, in which spy agencies collect and sift through the data of ISPs and telecoms to surveil targets. “This blurs the boundary between passive surveillance and actual intrusion,” DeGrippo says.

    For this particular group of FSB hackers, DeGrippo adds, it also suggests a powerful new weapon in their arsenal for targeting anyone within Russia’s borders. “It potentially shows how they think of Russia-based telecom infrastructure as part of their toolkit,” she says.

    According to Microsoft’s researchers, Turla’s technique exploits a certain web request browsers make when they encounter a “captive portal,” the windows that are most commonly used to gate-keep internet access in settings like airports, airplanes, or cafes, but also inside some companies and government agencies. In Windows, those captive portals reach out to a certain Microsoft website to check that the user’s computer is in fact online. (It’s not clear whether the captive portals used to hack Turla’s victims were in fact legitimate ones routinely used by the target embassies or ones that Turla somehow imposed on users as part of its hacking technique.)

    By taking advantage of its control of the ISPs that connect certain foreign embassy staffers to the internet, Turla was able to redirect targets so that they saw an error message that prompted them to download an update to their browser’s cryptographic certificates before they could access the web. When an unsuspecting user agreed, they instead installed a piece of malware that Microsoft calls ApolloShadow, which is disguised—somewhat inexplicably—as a Kaspersky security update.

    That ApolloShadow malware would then essentially disable the browser’s encryption, silently stripping away cryptographic protections for all web data the computer transmits and receives. That relatively simple certificate tampering was likely intended to be harder to detect than a full-featured piece of spyware, DeGrippo says, while achieving the same result.

    Devious group hacking ISPs Kremlins plant Russian spyware
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Olivia Carter
    • Website

    Olivia Carter is a staff writer at Verda Post, covering human interest stories, lifestyle features, and community news. Her storytelling captures the voices and issues that shape everyday life.

    Related Posts

    The Best Mushroom Gummies on the Market, Lab-Approved (2025)

    September 21, 2025

    ‘We’re here to help’: how Ofcom is urging porn sites to follow the Online Safety Act | Pornography

    September 21, 2025

    Some iPhone 17 models are reportedly prone to very visible scratches

    September 21, 2025

    TechCrunch Mobility: The two robotaxi battlegrounds that matter

    September 21, 2025

    14 Best Fitness Trackers (2025), Tested and Reviewed

    September 21, 2025

    Apple now controls all core iPhone chips, prioritizing AI workloads

    September 21, 2025
    Leave A Reply Cancel Reply

    Medium Rectangle Ad
    Top Posts

    Glastonbury 2025: Saturday with Charli xcx, Kneecap, secret act Patchwork and more – follow it live! | Glastonbury 2025

    June 28, 20258 Views

    In Bend, Oregon, Outdoor Adventure Belongs to Everyone

    August 16, 20257 Views

    The Underwater Scooter Divers and Snorkelers Love

    August 13, 20257 Views
    Don't Miss

    The Best Mushroom Gummies on the Market, Lab-Approved (2025)

    September 21, 2025

    Compare Top 3 Mushroom GummiesHonorable MentionsCourtesy of Alice MushroomsAlice Mushrooms Nightcap for $59: Mushroom chocolate…

    Optimo DJ JD Twitch dies after being diagnosed with brain tumour

    September 21, 2025

    Blue Jays clinch MLB playoff berth, still targeting AL East division title and American League’s best record

    September 21, 2025

    News live: Netanyahu warns Albanese to ‘stand by’ after Australia recognises Palestine; Sydney trains to ban some ebikes | Australia news

    September 21, 2025
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    Medium Rectangle Ad
    Most Popular

    Glastonbury 2025: Saturday with Charli xcx, Kneecap, secret act Patchwork and more – follow it live! | Glastonbury 2025

    June 28, 20258 Views

    In Bend, Oregon, Outdoor Adventure Belongs to Everyone

    August 16, 20257 Views

    The Underwater Scooter Divers and Snorkelers Love

    August 13, 20257 Views
    Our Picks

    As a carer, I’m not special – but sometimes I need to be reminded how important my role is | Natasha Sholl

    June 27, 2025

    Anna Wintour steps back as US Vogue’s editor-in-chief

    June 27, 2025

    Elon Musk reportedly fired a key Tesla executive following another month of flagging sales

    June 27, 2025
    Recent Posts
    • The Best Mushroom Gummies on the Market, Lab-Approved (2025)
    • Optimo DJ JD Twitch dies after being diagnosed with brain tumour
    • Blue Jays clinch MLB playoff berth, still targeting AL East division title and American League’s best record
    • News live: Netanyahu warns Albanese to ‘stand by’ after Australia recognises Palestine; Sydney trains to ban some ebikes | Australia news
    • The Guardian view on Wedgwood’s challenges: potteries face an existential crisis | Industrial policy
    • About Us
    • Disclaimer
    • Get In Touch
    • Privacy Policy
    • Terms and Conditions
    2025 Voxa News. All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.