logo

Russia Hacked Routers to Steal Microsoft Office Tokens

ID: f5123eea-f736-516e-a281-002ed9aa3084

STIX ID: report--f5123eea-f736-516e-a281-002ed9aa3084

Feed Name: Krebs on Security

Threat Score
90/100

Date Published: 2026-04-07

Date Updated: 2026-04-19

Author: BrianKrebs

...
...

Forest Blizzard (APT28/Fancy Bear), a GRU-linked threat actor, exploited known vulnerabilities in outdated SOHO routers (primarily Mikrotik and TP-Link) to change DNS settings at scale and redirect traffic to attacker-controlled DNS servers. By harvesting OAuth authentication tokens and performing AiTM on TLS connections to Microsoft Outlook on the web, the campaign—peaking in December 2025—compromised over 18,000 routers and affected 200+ organizations, focusing on government ministries, law enforcement, and third-party email providers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.