https://www.theregister.com/2025/07/31/kremlin_goons_caught_abusing_isps/
Russian cyberspies are abusing local internet service providers’ networks to target foreign embassies in Moscow and collect intel from diplomats’ devices, according to a Microsoft Threat Intelligence warning. Redmond detailed the ongoing cyber-espionage campaign, active since at least 2024, and carried out by a Kremlin-backed group it tracks as Secret Blizzard (aka VENOMOUS BEAR, Turla, WRAITH, ATG26) in a Thursday report; Microsoft declined to say how many organizations were targeted, or successfully infected, in this campaign. …
Regards