logo

Russia Hacked Routers to Steal Microsoft Office Tokens

ID: 9813d0b2-51e1-5de5-8848-70ff75fd3987

STIX ID: report--9813d0b2-51e1-5de5-8848-70ff75fd3987

Feed Name: Security Boulevard

Threat Score
90/100

Date Published: 2026-04-07

Date Updated: 2026-04-22

Author: BrianKrebs

...
...

Microsoft and Black Lotus Labs warn that Russia-linked GRU actors known as Forest Blizzard (APT28/Fancy Bear) conducted a large-scale DNS hijacking campaign by exploiting known flaws in older Mikrotik and TP-Link SOHO routers to redirect DNS to attacker-controlled servers, enabling AiTM interception of OAuth tokens for Microsoft Office/Outlook web; the covert campaign impacted over 18,000 routers, around 200 organizations (including government ministries) and several thousand consumer devices without deploying malware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.