logo

Authorities disrupt router DNS hijacks used to steal Microsoft 365 logins

ID: 6cbb9962-ed28-5010-95db-74b9f1d510f1

STIX ID: report--6cbb9962-ed28-5010-95db-74b9f1d510f1

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-04-07

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

An international takedown disrupted 'FrostArmada,' an APT28 campaign that hijacked DNS on compromised MikroTik, TP-Link and other routers to route authentication traffic through attacker-controlled proxies, enabling adversary-in-the-middle collection of Microsoft 365 credentials and OAuth tokens; the activity affected ~18,000 devices across 120 countries, targeted government and hosting entities, and included published IoCs and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.