Russian Hackers Impersonate Cyber Firm To Spy On Embassies
A Russian state-linked group, Turla, used local internet providers and fake Kaspersky tools to launch a major cyber-espionage campaign targeting foreign embassies in Moscow.
July 31, 2025Clash Report

ClashReport
Microsoft stated that Turla—also known as Secret Blizzard—used access to Russian internet service providers to reroute embassy traffic and deliver malware payloads. These tools posed as legitimate cybersecurity software associated with the Russian firm Kaspersky. A spokesperson for Kaspersky denied involvement, emphasizing that trusted brand names are often exploited without consent and advised users to only download apps from verified sources.
Once deployed, the ApolloShadow malware decrypted encrypted internet traffic, allowing the hackers to access usernames, passwords, and browsing records. Microsoft did not name specific embassy targets but described the campaign as extensive and sophisticated.
Espionage Group Tied To Russian Intelligence
Turla has operated for more than 25 years and is widely considered one of the most persistent hacking units in the world. The U.S. Department of Justice previously linked the group to the Russian Federal Security Service (FSB), and dismantled a large part of its infrastructure in 2023. Analysts believe Turla benefits from Russia’s legal surveillance framework, especially systems like SORM, which enables FSB and police to intercept communications nationwide.
The hacking campaign occurs during heightened international scrutiny of Russia’s global cyber posture and its war in Ukraine. In parallel, President Vladimir Putin is tightening domestic digital controls, promoting a state-approved internet app ecosystem and threatening to ban encrypted messaging platforms like WhatsApp.
Sources:
Related Topics
Related News
Russia’s Teenage Spy Exposes Crypto-Funded Espionage Network
America
June 2025
Ukraine Warns Teens: “The Enemy Is in Your Phone”
Ukraine - Russia War
June 2025
Russia Recruits Ukrainian Teens for Espionage
Ukraine - Russia War
June 2025
US Industrial Giants Shift Focus To Data Centres
America
July 2025
KLM To Lend Pilots To Dutch Air Force Amid Defense Push
Defense
July 2025
Russia Allows Foreigners to Join Army Amid War
Asia-Pasific
July 2025