Russian Military Hackers Hijack Thousands of Home Routers for Global Espionage
ID: e44a75ad-3d02-5008-9ee5-92766e287b8a
STIX ID: report--e44a75ad-3d02-5008-9ee5-92766e287b8a
Feed Name: securityonline.info
Microsoft Threat Intelligence reports that the Russian military-linked APT Forest Blizzard (and subgroup Storm-2754) has been compromising SOHO/home routers since at least August 2025 to hijack DNS at scale (over 5,000 consumer devices and 200 organizations). By configuring actor-controlled DNS resolvers and using dnsmasq, the group gains persistent passive visibility and performs selective AiTM attacks—spoofing DNS for high-value targets, presenting invalid TLS certificates, and intercepting plaintext if users ignore warnings—specifically targeting Microsoft 365 domains and multiple government organizations, highlighting the critical risk posed by insecure home networking infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
