ApolloShadow
- Malware type
- spyware
- Family
- Malware family
- Last IoC activity
- 2026-04-24 08:14:54
- Profile updated
- 2026-07-07 14:44:48
Targeted industries: government-and-public-sector
Targeted regions: country_code:ru
Context
According to Microsoft, ApolloShadow has the capability to install a trusted root certificate to trick devices into trusting malicious actor-controlled sites, enabling Secret Blizzard to maintain persistence on diplomatic devices, likely for intelligence collection. It has been used in a campaign where Secret Blizzard has been targeting embassies located in Moscow using an adversary-in-the-middle (AiTM) position.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Apollo Shadow (report)
- Microsoft — Frozen In Transit Secret Blizzards Aitm Campaign Against Diplomats (report)