Russian hacker group using Internet service providers to spy on foreign embassies
August 2, 2025 3 Comments
A HACKER GROUP LINKED to Russia’s Federal Security Service (FSB) has compromised Russia’s domestic internet infrastructure and is using it to target foreign diplomats stationed in Russia. According to a report, published last week by Microsoft Threat Intelligence, the hacker group behind this operation is Turla, also known as Snake, Venomous Bear, Group 88, Waterbug, and Secret Blizzard. Analysts have linked the group with “some of the most innovative hacking feats in the history of cyberespionage”.
Turla began its attempt to compromise a host of Russian internet service providers in February, according to Microsoft’s report. The group’s apparent goal has been to gain access to the software that enables Russian security agencies to legally intercept internet traffic, following the issuance of warrants by judges. This software is governed by Russia’s System for Operative Investigative Activities (SORM), which became law in 1995, under the presidency of Boris Yeltsin. All local, state, and federal government agencies in Russia use the SORM system to facilitate court-authorized telecommunications surveillance.
According to Microsoft, targeted Internet users receive an error message prompting them to update their browser’s cryptographic certificate. Consent by the user results in the targeted computer downloading and installing a malware. Termed ApolloShadow by Microsoft, the malware is disguised as a security update from Kaspersky, Russia’s most widely known antivirus software provider. Once installed the malware gives the hackers access to the content of the targeted user’s secure communications.
The Microsoft report states that, although Turla has been involved in prior attacks against diplomatic targets in Russia and abroad, this is the first time that the hacker group has been confirmed to have the capability to attack its targets at the Internet Service Provider (ISP) level. In doing so, Turla has been able to incorporate Russia’s domestic telecommunications infrastructure into its attack tool-kit, the report states. The report does not name the diplomatic facilities or the countries whose diplomats have been targeted by Turla hackers. But it warns that all “diplomatic personnel using local [internet service providers] or telecommunications services in Russia are highly likely targets” of the group.
► Author: Joseph Fitsanakis | Date: 02 August 2025 | Permalink
HACKERS HAVE COMPROMISED A website used by the United States Intelligence Community (IC) to solicit sensitive contracts from the private sector,
THE MOSSAD, ISRAEL’S PRIMARY foreign-intelligence agency, played a crucial role in Israel’s most recent attack on Iran. It is clear that, without unique intelligence on key Iranian figures and nuclear sites, much of it gathered by the Mossad, the Israeli Air Force could not have been so precise and deadly against Iranian targets.
A GROUP OF RESEARCHERS in Finland have managed to outline the structure and geographic footprint of a highly secretive Russian signals intelligence (SIGINT) unit by studying commemorative badges issued by the Russian government. The research group, known as
THE
THE GOVERNMENT OF ISRAEL recently appointed a new acting chief at the Israel Security Agency (ISA, also known as Shabak or Shin Bet). Identified only by their first initial, “S.”, this individual is one of the deputies of the
THE MOSSAD, ISRAEL’S PRIMARY external intelligence agency, had set up forward-operating bases deep inside Iranian territory several years prior to last week’s attacks, which targeted Iran’s military and nuclear infrastructure. In some cases, Mossad operatives, including commando forces, were operating inside the vicinity of the Iranian capital Tehran for months prior to June 13, according to Israeli media outlets.
ON MAY 26, THE Austrian domestic intelligence service,
and specialized essays about certain relevant topics. Traditionally the media and public give most attention to those parts of the report that deal with extremism and terrorism of all kinds inside Austria.
an unwanted wrench in President [Donald] Trump’s negotiation process to resolve the atomic crisis with Iran’s rulers because the data outlined in the report suggests the regime will not abandon its drive to secure a nuclear weapon.”
TWO RUSSIAN SPIES USED forged documents acquired in Brazil in order to live in Portugal for years and use it as a base from where to conduct espionage, according to an investigation by Portuguese counterintelligence. The spies were husband-and-wife team Vladimir Aleksandrovich Danilov and Yekaterina Leonidovna Danilova, both in their 30s.
EARLIER THIS WEEK THE High Court of Israel delivered its ruling regarding the
THE ADMINISTRATION OF UNITED States President Donald Trump has ordered American intelligence agencies to focus on Greenland, while also mulling a plan to establish a formal association with the island territory. The Wall Street Journal
VETERAN ISRAELI INTELLIGENCE OFFICER Ronen Bar, who has led the Israeli Security Agency (ISA, more widely known as the Shin Bet) since 2021, has submitted an affidavit to Israel’s Supreme Court, accusing Prime Minister Benjamin Netanyahu of serious misconduct. Netanyahu fired Bar in March, but the Supreme Court later
protesting activists, because, according to Netanyahu, they were “following security targets”.
A 21-YEAR-OLD American citizen, whose mother is a senior Central Intelligence Agency (CIA) official, died while fighting with the Russian military in Ukraine in 2024, according to a news report. Late last week, the CIA confirmed the accuracy of the story while requesting that the media afford the bereaved family “privacy at this difficult time”.






Israeli intelligence using Microsoft servers to store intercepted phone call data
August 11, 2025 by intelNews 2 Comments
Citing conversation with 11 sources from Microsoft and within Israel, the investigation reveals that Israel Defense Forces (IDF) Unit 8200 is the primary force behind the interception and data storage project. Operating under Aman, Israel’s military intelligence directorate, Unit 8200 is responsible for collecting signals intelligence (SIGINT), cyber warfare, and code decryption, among other tasks.
Israeli security sources cited in the report explain that the commander of Unit 8200, Brigadier General Yossi Sriel, approached Microsoft because the Israeli intelligence unit lacked enough storage space and processing power to store “billions of files”. General Sriel has led a large-budget project that has significantly expanded the scope of information-gathering on Palestinians and has integrated various databases.
In November 2021, an meeting, described in the report as “extraordinary”, took place at Microsoft’s headquarters in Seattle, Washington. On one side were Microsoft Chief Operating Officer, Satya Nadella, and other company executives, while on the other side were General Sriel and other senior officials of Unit 8200. The agenda centered on a plan, promoted by Sriel, to transfer intelligence information held by the Unit to the computing giant’s servers. According to an internal Microsoft document, which was leaked by The Guardian, Sriel requested the transfer to Microsoft’s cloud of 70% of the unit’s data, including “secret and top secret” data.
The meeting allegedly led to the development of one of the world’s most invasive surveillance systems, which has been employed by Israel to monitor Palestinians in Gaza and the West Bank. According to documents cited by The Guardian, as of July this year, 11,500 terabytes of Israeli military data—equivalent to 862 billion documents or 195 million hours of audio—were stored on Microsoft Azure public cloud servers in the Netherlands. A smaller portion of the data was stored in Ireland and Israel. Read more of this post
Filed under Expert news and commentary on intelligence, espionage, spies and spying Tagged with call data, communications interception, databases, IDF, Israel, Israel Military Intelligence, Microsoft, News, Unit 8200, Yossi Sriel