logo

Russian Hackers Exploiting Home and Small-office Routers in Massive DNS hijacking Attack

ID: 980d7088-bb69-5c5a-b681-b3bc7d0110d6

STIX ID: report--980d7088-bb69-5c5a-b681-b3bc7d0110d6

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-04-07

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Microsoft observed Forest Blizzard (APT28/Strontium) conducting a widespread campaign since at least August 2025 that compromises poorly secured SOHO/home routers to replace DNS resolvers with actor-controlled servers, enabling passive DNS collection at scale and selective TLS Adversary-in-the-Middle interceptions—impacting over 200 organizations and more than 5,000 consumer devices and targeting sectors including government, IT, telecommunications, and energy; Microsoft provides mitigations such as updating router firmware, changing default credentials, auditing DNS settings, enforcing VPNs, and training users not to bypass TLS certificate warnings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.