Close Menu
  • Home
  • News
    • Local
    • State
    • National
    • World
    • HBCUs
  • Events
    • Submit Your Event
    • Promote Your Event
  • Weather
  • Traffic
  • Sports
  • Politics
  • Lifestyle
    • Faith
    • Beauty
    • Fashion
    • Food
    • Art & Literature
    • Travel
    • Senior Living
    • Black History
  • Health
  • Business
    • Investing
    • Gaming
    • Education
    • Entertainment
    • Tech
    • Real Estate
  • More
    • Health Inspections
    • A List of Our Online Black Newspapers in America
We're Social
  • Twitter
  • Facebook
  • Instagram
  • YouTube
  • LinkedIn
  • TikTok

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

Trending
  • Quantum computer will certainly make cryptography outdated. However computer system researchers are functioning to make them unhackable.
  • Brownish Sugar Extra Pound Cake
  • 3 Historic Minutes When Our Chosen Authorities In Fact Did the Right Point.
  • Sagora Senior Games
  • Midcentury Modern Gold Mines: 5 Architectural Gems That Promise a Huge Return on Investment
  • City to Hold Informational Session on Forsyth Park Gathering Space Concept • Savannah Herald
  • How Trump’s Enemies Became His Disciples
  • Diarrha N’Diaye Talks Myths Of Black Founders And Venture Capital
Facebook X (Twitter) Instagram YouTube LinkedIn
Login
Savannah HeraldSavannah Herald
  • Home
  • News
    • Local
    • State
    • National
    • World
    • HBCUs
  • Events
    • Submit Your Event
    • Promote Your Event
  • Weather
  • Traffic
  • Sports
  • Politics
  • Lifestyle
    • Faith
    • Beauty
    • Fashion
    • Food
    • Art & Literature
    • Travel
    • Senior Living
    • Black History
  • Health
  • Business
    • Investing
    • Gaming
    • Education
    • Entertainment
    • Tech
    • Real Estate
  • More
    • Health Inspections
    • A List of Our Online Black Newspapers in America
Savannah HeraldSavannah Herald
Home » Microsoft catches Russian hackers targeting foreign embassies
Tech

Microsoft catches Russian hackers targeting foreign embassies

Savannah HeraldBy Savannah HeraldSeptember 3, 20252 Mins Read
Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
Microsoft catches Russian hackers targeting foreign embassies
Share
Facebook Twitter LinkedIn Pinterest Email

Tech Trends & Innovation: The Latest in Tech News

Once behind the captive portal, the page initiates the Windows Test Connectivity Status Indicator, a legitimate service that determines whether a device has Internet access by sending an HTTP GET request to hxxp://www.msftconnecttest[.]com/redirect. That site, in turn, redirects the browser to msn[.]com. As Thursday’s post explained:

Once the system opens the browser window to this address, the system is redirected to a separate actor-controlled domain that likely displays a certificate validation error which prompts the target to download and execute ApolloShadow. Following execution, ApolloShadow checks for the privilege level of the ProcessToken and if the device is not running on default administrative settings, then the malware displays the user access control (UAC) pop-up window to prompt the user to install certificates with the file name CertificateDB.exe, which masquerades as a Kaspersky installer to install root certificates and allow the actor to gain elevated privileges in the system.

The following diagram illustrates the infection chain:

ApolloShadow invokes the GetTokenInformationType API to check if it has sufficient system rights to install the root certificate. If not, the malware uses a sophisticated process that spoofs a page at hxxp://timestamp.digicert[.]com/registered, which in turn sends the system a second-stage payload in the form of a VBScript.

Once decoded, ApolloShadow relaunches itself and presents the user with a User Access Control window seeking to elevate its system access. (Microsoft provided many more technical details about the technique in Thursday’s post.)

If ApolloShadow already has sufficient system rights, the malware configures all networks the host connects to as private.

“This induces several changes including allowing the host device to become discoverable and relaxing firewall rules to enable file sharing,” Microsoft explained. “While we did not see any direct attempts for lateral movement, the main reason for these modifications is likely to reduce the difficulty of lateral movement on the network.” (The Microsoft post also provided technical details about this technique.)

Microsoft said the ability to cause infected devices to trust malicious sites allows the threat actor to maintain persistence, likely for use in intelligence collection.

The company is advising all customers operating in Moscow, particularly sensitive organizations, to tunnel their traffic through encrypted tunnels that connect to a trusted ISP.

Read the full article from the original source


AI and Machine Learning artificial intelligence Consumer Electronics Cybersecurity Updates Data Privacy Digital Trends Enterprise Technology Future of Work Gadget Reviews Green Tech Mobile Tech Robotics News Science and Technology Silicon Valley News Software Development Startups and Tech Tech Industry Insights Tech Innovation Tech Policy Technology News
Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
Savannah Herald
  • Website

Related Posts

Science November 13, 2025

Woodlands with varied water-use techniques reveal higher dry spell resistance

Tech November 14, 2025

Andela CEO talks about the need for ‘borderless talent’ amid work visa limitations – Computerworld

Politics November 12, 2025

Is Ben Shapiro Gay? Truth Behind the Rumors & His Latest Life Updates

Tech November 11, 2025

iOS 26.1 Is Here, and It Brings All These Changes to Your iPhone

Real Estate November 4, 2025

Aivre launches AI-driven appraisal platform

Tech November 2, 2025

The Rise of Micro-Influencers: Small Audiences, Big Impact

Comments are closed.

Don't Miss
Education September 3, 2025By Savannah Herald04 Mins Read

Vivian Ayers Allen, Pulitzer-Nominated Poet and ‘Hidden Figure’ Honored for Apollo 11, Dies at 102

September 3, 2025

From Campus to Classroom: Stories That Shape Education CHESTER, S.C. — Vivian Ayers Allen—a Pulitzer…

Ideal Web Carriers in Illinois

August 28, 2025

Nikole Hannah-Jones Calls Out Jillian Michaels’ Slavery Remarks

November 11, 2025

Trump Suffers Huge Loss in Efforts to Speedily Deport People

August 28, 2025

The curious rise of giant tablets on wheels

August 28, 2025
Archives
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
Categories
  • Art & Literature
  • Beauty
  • Black History
  • Business
  • Climate
  • Education
  • Entertainment
  • Faith
  • Fashion
  • Food
  • Gaming
  • HBCUs
  • Health
  • Health Inspections
  • Home & Garden
  • Investing
  • Local
  • Lowcountry News
  • National
  • News
  • Obituaries
  • Politics
  • Real Estate
  • Science
  • Senior Living
  • Sports
  • SSU Homecoming 2024
  • State
  • Tech
  • Travel
  • World
Savannah Herald Newsletter

Subscribe to Updates

A round up interesting pic’s, post and articles in the C-Port and around the world.

About Us
About Us

The Savannah Herald is your trusted source for the pulse of Coastal Georgia and the Low County of South Carolina. We're committed to delivering timely news that resonates with the African American community.

From local politics to business developments, we're here to keep you informed and engaged. Our mission is to amplify the voices and stories that matter, shining a light on our collective experiences and achievements.
We cover:
🏛️ Politics
💼 Business
🎭 Entertainment
🏀 Sports
🩺 Health
💻 Technology
Savannah Herald: Savannah's Black Voice 💪🏾

Our Picks

How To Make A Statement Over 40 — THE DAILEIGH

September 3, 2025

Embracing Our Beauty and Power

October 21, 2025

Palestinians in Gaza danger painful trip in look for food: NPR

August 28, 2025

Tips on how to Have a good time Mom’s Day in a Senior Dwelling Group

August 29, 2025

Tropical Storm Erin forms, could become first hurricane in Atlantic Ocean this season

August 28, 2025
Categories
  • Art & Literature
  • Beauty
  • Black History
  • Business
  • Climate
  • Education
  • Entertainment
  • Faith
  • Fashion
  • Food
  • Gaming
  • HBCUs
  • Health
  • Health Inspections
  • Home & Garden
  • Investing
  • Local
  • Lowcountry News
  • National
  • News
  • Obituaries
  • Politics
  • Real Estate
  • Science
  • Senior Living
  • Sports
  • SSU Homecoming 2024
  • State
  • Tech
  • Travel
  • World
  • Privacy Policies
  • Disclaimers
  • Terms and Conditions
  • About Us
  • Contact Us
  • Opt-Out Preferences
  • Accessibility Statement
Copyright © 2002-2025 Savannahherald.com All Rights Reserved. A Veteran-Owned Business

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login below or Register Now.

Lost password?

Register Now!

Already registered? Login.

A password will be e-mailed to you.