ApolloShadow

Malware type
spyware
Family
Malware family
Last IoC activity
2026-04-24 08:14:54
Profile updated
2026-07-07 14:44:48

Targeted industries: government-and-public-sector

Targeted regions: country_code:ru

Context

According to Microsoft, ApolloShadow has the capability to install a trusted root certificate to trick devices into trusting malicious actor-controlled sites, enabling Secret Blizzard to maintain persistence on diplomatic devices, likely for intelligence collection. It has been used in a campaign where Secret Blizzard has been targeting embassies located in Moscow using an adversary-in-the-middle (AiTM) position.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Apollo Shadow (report)
  • Microsoft — Frozen In Transit Secret Blizzards Aitm Campaign Against Diplomats (report)

External references