Russian hacker group using Internet service providers to spy on foreign embassies
August 2, 2025 3 Comments
A HACKER GROUP LINKED to Russia’s Federal Security Service (FSB) has compromised Russia’s domestic internet infrastructure and is using it to target foreign diplomats stationed in Russia. According to a report, published last week by Microsoft Threat Intelligence, the hacker group behind this operation is Turla, also known as Snake, Venomous Bear, Group 88, Waterbug, and Secret Blizzard. Analysts have linked the group with “some of the most innovative hacking feats in the history of cyberespionage”.
Turla began its attempt to compromise a host of Russian internet service providers in February, according to Microsoft’s report. The group’s apparent goal has been to gain access to the software that enables Russian security agencies to legally intercept internet traffic, following the issuance of warrants by judges. This software is governed by Russia’s System for Operative Investigative Activities (SORM), which became law in 1995, under the presidency of Boris Yeltsin. All local, state, and federal government agencies in Russia use the SORM system to facilitate court-authorized telecommunications surveillance.
According to Microsoft, targeted Internet users receive an error message prompting them to update their browser’s cryptographic certificate. Consent by the user results in the targeted computer downloading and installing a malware. Termed ApolloShadow by Microsoft, the malware is disguised as a security update from Kaspersky, Russia’s most widely known antivirus software provider. Once installed the malware gives the hackers access to the content of the targeted user’s secure communications.
The Microsoft report states that, although Turla has been involved in prior attacks against diplomatic targets in Russia and abroad, this is the first time that the hacker group has been confirmed to have the capability to attack its targets at the Internet Service Provider (ISP) level. In doing so, Turla has been able to incorporate Russia’s domestic telecommunications infrastructure into its attack tool-kit, the report states. The report does not name the diplomatic facilities or the countries whose diplomats have been targeted by Turla hackers. But it warns that all “diplomatic personnel using local [internet service providers] or telecommunications services in Russia are highly likely targets” of the group.
► Author: Joseph Fitsanakis | Date: 02 August 2025 | Permalink
A GROUP OF RESEARCHERS in Finland have managed to outline the structure and geographic footprint of a highly secretive Russian signals intelligence (SIGINT) unit by studying commemorative badges issued by the Russian government. The research group, known as
THE MOSSAD, ISRAEL’S PRIMARY external intelligence agency, had set up forward-operating bases deep inside Iranian territory several years prior to last week’s attacks, which targeted Iran’s military and nuclear infrastructure. In some cases, Mossad operatives, including commando forces, were operating inside the vicinity of the Iranian capital Tehran for months prior to June 13, according to Israeli media outlets.
TWO RUSSIAN SPIES USED forged documents acquired in Brazil in order to live in Portugal for years and use it as a base from where to conduct espionage, according to an investigation by Portuguese counterintelligence. The spies were husband-and-wife team Vladimir Aleksandrovich Danilov and Yekaterina Leonidovna Danilova, both in their 30s.
THE ADMINISTRATION OF UNITED States President Donald Trump has ordered American intelligence agencies to focus on Greenland, while also mulling a plan to establish a formal association with the island territory. The Wall Street Journal
A 21-YEAR-OLD American citizen, whose mother is a senior Central Intelligence Agency (CIA) official, died while fighting with the Russian military in Ukraine in 2024, according to a news report. Late last week, the CIA confirmed the accuracy of the story while requesting that the media afford the bereaved family “privacy at this difficult time”.
BRITAIN’S SECURITY AGENCIES HAVE reportedly warned civil servants and parliamentarians that public places located near government buildings may be bugged by foreign intelligence agencies. The warning covers the SW1 postcode district of southwest London, which encompasses the City of Westminster and includes the Houses of Parliament, the Office of the Prime Minister at 10 Downing Steet, and Whitehall. The latter is home to several ministries and departments, including the Foreign and Commonwealth Office, the Cabinet office, and the Ministry of Defense.
OVER 250 FORMER MEMBERS of the Mossad, Israel’s external spy agency, have drafted an open
THE REUTERS NEWS AGENCY has disclosed more information about an alleged plot by Russian intelligence to detonate bombs on cargo flights from Europe to North America. Initial details of the plot emerged in October 2024, when it was
FOUR TAIWANESE SOLDIERS WITH access to “extremely sensitive” secrets have received jail sentences for spying for Chinese intelligence, as Taiwanese authorities have warned of a sharp rise in Chinese espionage cases. Three of the soldiers had been detailed to the security of the Office of the President, while the fourth soldier was a member of staff at the Taiwanese Ministry of National Defense’s Information and Telecommunications Command.
BRITISH MEDIA REPORTED THE death on Saturday of Oleg Gordievsky, arguably the most significant double spy of the closing stages of the Cold War, whose disclosures informed the highest executive levels of the West. Having joined the Soviet KGB in 1963, Gordievsky became increasingly disillusioned with the Soviet system of rule following the 1968 invasion of Czechoslovakia.
THE EUROPEAN UNION IS considering building its own military satellite network in an effort to reduce or eliminate its reliance on American satellite capabilities, according to reports. The London-based Financial Times newspaper 






Soldier with far-right links becomes first convicted spy in New Zealand history
August 19, 2025 1 Comment
According to reports, a member of the New Zealand Defence Force, who has not been named, drew the attention of the authorities in the aftermath of the 2019 Christchurch shooting. The attack was carried out by Australian white supremacist Brenton Tarrant, who stormed a mosque with an automatic weapon, killing 51 and injuring nearly 100 people. The terrorist attack sparked a widespread investigation into far-right militancy in the Australian and New Zealand armed forces, which continues to this day.
The soldier was found to have contacts with a number of local far-right groups, including the Dominion Movement and Action Zealandia. Government prosecutors said that, while observing the soldier’s activities, government agents found out that he had “made contact with a third party, indicating that he was a soldier” and signaling his desire to defect to a foreign country. They eventually approached the soldier using an undercover officer who pretended to be a representative of the country whose officials the soldier had previously contacted. The soldier told the undercover officer that he was prepared to “get a covert device into army headquarters” and offered to provide “mapping and photographs” of classified government facilities.
During his trial, the soldier pled guilty, admitting that he had tied to spy for a foreign government, and adding that his ultimate goal was to “leave New Zealand and get to what I thought was safety”. Following the soldier’s conviction, the three-judge military panel said it would announce the sentence later this week. The country for which the convicted soldier offered to spy has not been named.
► Author: Joseph Fitsanakis | Date: 18 August 2025 | Permalink
Filed under Expert news and commentary on intelligence, espionage, spies and spying Tagged with Bill Sutch, Christchurch (New Zealand), counterintelligence, espionage, New Zealand, New Zealand Defence Forces, News, William Sutch