The Russian state hacker group known as Turla has carried out some of the most innovative hacking feats in the history of cyberespionage, hiding their malwareâs communications in satellite connections or hijacking other hackersâ operations to cloak their own data extraction. When theyâre operating on their home turf, however, it turns out theyâve tried an equally remarkable, if more straightforward, approach: They appear to have used their control of Russiaâs internet service providers to directly plant spyware on the computers of their targets in Moscow.
Microsoftâs security research team focused on hacking threats today published a report detailing an insidious new spy technique used by Turla, which is believed to be part of the Kremlinâs FSB intelligence agency. The group, which is also known as Snake, Venomous Bear, or Microsoftâs own name, Secret Blizzard, appears to have used its state-sanctioned access to Russian ISPs to meddle with internet traffic and trick victims working in foreign embassies operating in Moscow into installing the groupâs malicious software on their PCs. That spyware then disabled encryption on those targetsâ machines so that data they transmitted across the internet remained unencrypted, leaving their communications and credentials like usernames and passwords entirely vulnerable to surveillance by those same ISPsâand any state surveillance agency with which they cooperate.
Sherrod DeGrippo, Microsoftâs director of threat intelligence strategy, says the technique represents a rare blend of targeted hacking for espionage and governmentsâ older, more passive approach to mass surveillance, in which spy agencies collect and sift through the data of ISPs and telecoms to surveil targets. âThis blurs the boundary between passive surveillance and actual intrusion,â DeGrippo says.
For this particular group of FSB hackers, DeGrippo adds, it also suggests a powerful new weapon in their arsenal for targeting anyone within Russiaâs borders. âIt potentially shows how they think of Russia-based telecom infrastructure as part of their toolkit,â she says.
According to Microsoftâs researchers, Turlaâs technique exploits a certain web request browsers make when they encounter a âcaptive portal,â the windows that are most commonly used to gate-keep internet access in settings like airports, airplanes, or cafes, but also inside some companies and government agencies. In Windows, those captive portals reach out to a certain Microsoft website to check that the userâs computer is in fact online. (Itâs not clear whether the captive portals used to hack Turlaâs victims were in fact legitimate ones routinely used by the target embassies or ones that Turla somehow imposed on users as part of its hacking technique.)
By taking advantage of its control of the ISPs that connect certain foreign embassy staffers to the internet, Turla was able to redirect targets so that they saw an error message that prompted them to download an update to their browserâs cryptographic certificates before they could access the web. When an unsuspecting user agreed, they instead installed a piece of malware that Microsoft calls ApolloShadow, which is disguisedâsomewhat inexplicablyâas a Kaspersky security update.
That ApolloShadow malware would then essentially disable the browserâs encryption, silently stripping away cryptographic protections for all web data the computer transmits and receives. That relatively simple certificate tampering was likely intended to be harder to detect than a full-featured piece of spyware, DeGrippo says, while achieving the same result.

