logo

Russian Military Hackers Hijack Thousands of Home Routers for Global Espionage

ID: e44a75ad-3d02-5008-9ee5-92766e287b8a

STIX ID: report--e44a75ad-3d02-5008-9ee5-92766e287b8a

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-08

Date Updated: 2026-04-23

Author: Ddos

...
...

Microsoft Threat Intelligence reports that the Russian military-linked APT Forest Blizzard (and subgroup Storm-2754) has been compromising SOHO/home routers since at least August 2025 to hijack DNS at scale (over 5,000 consumer devices and 200 organizations). By configuring actor-controlled DNS resolvers and using dnsmasq, the group gains persistent passive visibility and performs selective AiTM attacks—spoofing DNS for high-value targets, presenting invalid TLS certificates, and intercepting plaintext if users ignore warnings—specifically targeting Microsoft 365 domains and multiple government organizations, highlighting the critical risk posed by insecure home networking infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.