logo

SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks

ID: 9e98725f-9f3a-5187-bdaf-f080c67f6aa4

STIX ID: report--9e98725f-9f3a-5187-bdaf-f080c67f6aa4

Feed Name: Microsoft Security

Threat Score
88/100

Date Published: 2026-04-07

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Forest Blizzard (Storm-2754), a Russian military-linked threat actor, has been exploiting insecure small-office/home-office routers since at least August 2025 to change DNS settings and funnel DNS traffic to actor-controlled resolvers; this access has enabled large-scale DNS collection and selective TLS adversary-in-the-middle (AiTM) attacks—including interceptions against Microsoft Outlook on the web and targeted government servers—with Microsoft observing impacts to over 200 organizations and about 5,000 consumer devices and providing mitigation and hunting guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.