logo

Russia’s Forest Blizzard Is Abusing Home + Small Office Routers for Cred Theft

ID: d8842156-beca-5909-ba5d-4f91138fa686

STIX ID: report--d8842156-beca-5909-ba5d-4f91138fa686

Feed Name: The CyberWire

Threat Score
85/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

...
...

The Microsoft Threat Intelligence Podcast covers Forest Blizzard, a Russian state-linked actor that compromises unmanaged home and small office routers to hijack DNS traffic, enabling broad surveillance and targeted credential theft; the episode reviews evolving tactics (from brute force to token-based access and DNS hijacking), explains why unmanaged routers are a critical blind spot, and discusses downstream third-party risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.