Russian hacker group using Internet service providers to spy on foreign embassies
August 2, 2025 3 Comments
A HACKER GROUP LINKED to Russia’s Federal Security Service (FSB) has compromised Russia’s domestic internet infrastructure and is using it to target foreign diplomats stationed in Russia. According to a report, published last week by Microsoft Threat Intelligence, the hacker group behind this operation is Turla, also known as Snake, Venomous Bear, Group 88, Waterbug, and Secret Blizzard. Analysts have linked the group with “some of the most innovative hacking feats in the history of cyberespionage”.
Turla began its attempt to compromise a host of Russian internet service providers in February, according to Microsoft’s report. The group’s apparent goal has been to gain access to the software that enables Russian security agencies to legally intercept internet traffic, following the issuance of warrants by judges. This software is governed by Russia’s System for Operative Investigative Activities (SORM), which became law in 1995, under the presidency of Boris Yeltsin. All local, state, and federal government agencies in Russia use the SORM system to facilitate court-authorized telecommunications surveillance.
According to Microsoft, targeted Internet users receive an error message prompting them to update their browser’s cryptographic certificate. Consent by the user results in the targeted computer downloading and installing a malware. Termed ApolloShadow by Microsoft, the malware is disguised as a security update from Kaspersky, Russia’s most widely known antivirus software provider. Once installed the malware gives the hackers access to the content of the targeted user’s secure communications.
The Microsoft report states that, although Turla has been involved in prior attacks against diplomatic targets in Russia and abroad, this is the first time that the hacker group has been confirmed to have the capability to attack its targets at the Internet Service Provider (ISP) level. In doing so, Turla has been able to incorporate Russia’s domestic telecommunications infrastructure into its attack tool-kit, the report states. The report does not name the diplomatic facilities or the countries whose diplomats have been targeted by Turla hackers. But it warns that all “diplomatic personnel using local [internet service providers] or telecommunications services in Russia are highly likely targets” of the group.
► Author: Joseph Fitsanakis | Date: 02 August 2025 | Permalink
HACKERS HAVE COMPROMISED A website used by the United States Intelligence Community (IC) to solicit sensitive contracts from the private sector,
THE MOSSAD, ISRAEL’S PRIMARY foreign-intelligence agency, played a crucial role in Israel’s most recent attack on Iran. It is clear that, without unique intelligence on key Iranian figures and nuclear sites, much of it gathered by the Mossad, the Israeli Air Force could not have been so precise and deadly against Iranian targets.
A GROUP OF RESEARCHERS in Finland have managed to outline the structure and geographic footprint of a highly secretive Russian signals intelligence (SIGINT) unit by studying commemorative badges issued by the Russian government. The research group, known as
THE
TWO RUSSIAN SPIES USED forged documents acquired in Brazil in order to live in Portugal for years and use it as a base from where to conduct espionage, according to an investigation by Portuguese counterintelligence. The spies were husband-and-wife team Vladimir Aleksandrovich Danilov and Yekaterina Leonidovna Danilova, both in their 30s.
THE ADMINISTRATION OF UNITED States President Donald Trump has ordered American intelligence agencies to focus on Greenland, while also mulling a plan to establish a formal association with the island territory. The Wall Street Journal
A 21-YEAR-OLD American citizen, whose mother is a senior Central Intelligence Agency (CIA) official, died while fighting with the Russian military in Ukraine in 2024, according to a news report. Late last week, the CIA confirmed the accuracy of the story while requesting that the media afford the bereaved family “privacy at this difficult time”.
BRITAIN’S SECURITY AGENCIES HAVE reportedly warned civil servants and parliamentarians that public places located near government buildings may be bugged by foreign intelligence agencies. The warning covers the SW1 postcode district of southwest London, which encompasses the City of Westminster and includes the Houses of Parliament, the Office of the Prime Minister at 10 Downing Steet, and Whitehall. The latter is home to several ministries and departments, including the Foreign and Commonwealth Office, the Cabinet office, and the Ministry of Defense.
OVER 250 FORMER MEMBERS of the Mossad, Israel’s external spy agency, have drafted an open
THE REUTERS NEWS AGENCY has disclosed more information about an alleged plot by Russian intelligence to detonate bombs on cargo flights from Europe to North America. Initial details of the plot emerged in October 2024, when it was
FOUR TAIWANESE SOLDIERS WITH access to “extremely sensitive” secrets have received jail sentences for spying for Chinese intelligence, as Taiwanese authorities have warned of a sharp rise in Chinese espionage cases. Three of the soldiers had been detailed to the security of the Office of the President, while the fourth soldier was a member of staff at the Taiwanese Ministry of National Defense’s Information and Telecommunications Command.
THE EUROPEAN UNION IS considering building its own military satellite network in an effort to reduce or eliminate its reliance on American satellite capabilities, according to reports. The London-based Financial Times newspaper 






Israeli intelligence using Microsoft servers to store intercepted phone call data
August 11, 2025 by intelNews 2 Comments
Citing conversation with 11 sources from Microsoft and within Israel, the investigation reveals that Israel Defense Forces (IDF) Unit 8200 is the primary force behind the interception and data storage project. Operating under Aman, Israel’s military intelligence directorate, Unit 8200 is responsible for collecting signals intelligence (SIGINT), cyber warfare, and code decryption, among other tasks.
Israeli security sources cited in the report explain that the commander of Unit 8200, Brigadier General Yossi Sriel, approached Microsoft because the Israeli intelligence unit lacked enough storage space and processing power to store “billions of files”. General Sriel has led a large-budget project that has significantly expanded the scope of information-gathering on Palestinians and has integrated various databases.
In November 2021, an meeting, described in the report as “extraordinary”, took place at Microsoft’s headquarters in Seattle, Washington. On one side were Microsoft Chief Operating Officer, Satya Nadella, and other company executives, while on the other side were General Sriel and other senior officials of Unit 8200. The agenda centered on a plan, promoted by Sriel, to transfer intelligence information held by the Unit to the computing giant’s servers. According to an internal Microsoft document, which was leaked by The Guardian, Sriel requested the transfer to Microsoft’s cloud of 70% of the unit’s data, including “secret and top secret” data.
The meeting allegedly led to the development of one of the world’s most invasive surveillance systems, which has been employed by Israel to monitor Palestinians in Gaza and the West Bank. According to documents cited by The Guardian, as of July this year, 11,500 terabytes of Israeli military data—equivalent to 862 billion documents or 195 million hours of audio—were stored on Microsoft Azure public cloud servers in the Netherlands. A smaller portion of the data was stored in Ireland and Israel. Read more of this post
Filed under Expert news and commentary on intelligence, espionage, spies and spying Tagged with call data, communications interception, databases, IDF, Israel, Israel Military Intelligence, Microsoft, News, Unit 8200, Yossi Sriel