Logo
News Ababil
Explore
Global Intel (English)
Global Intel (English)VOICE
Bengali (বাংলা)
Spanish (Español)VOICE
French (Français)VOICE
German (Deutsch)
Arabic (العربية)
Hindi (हिन्दी)VOICE
Chinese (中文)
Japanese (日本語)
Russian (Русский)
SYS_NODE: ONLINE // Cyber Security

Russia Hacked Routers to Harvest Microsoft Office Tokens – Inside the Massive DNS Hijack

DECRYPTED BY: Kaelen Frost | TIMESTAMP: 2026-05-03 T 20:23:09 Z | [ 2 MIN READ ]
Russia Hacked Routers to Harvest Microsoft Office Tokens – Inside the Massive DNS Hijack
2 Min Read
Share

Russia hacked routers to siphon Microsoft Office OAuth tokens from thousands of users, security analysts reported.

How the DNS hijack unfolded

Researchers at Black Lotus Labs, the security arm of Lumen, discovered that the campaign peaked in December 2025, compromising ↓ 18,000 aging Mikrotik and TP‑Link devices. By exploiting unpatched DNS settings, the attackers redirected queries to servers they controlled, allowing a silent man‑in‑the‑middle grab of authentication tokens.

The operation, attributed to the GRU‑linked group known as Forest Blizzard (aka APT28 or Fancy Bear), required no malware drops. Once a router’s DNS was altered, every workstation on the local subnet automatically sent token requests through the hostile resolver, handing the adversary ↑ 5,000 consumer devices and over 200 enterprises full‑account access.

“They didn’t need a fancy payload; they used old‑school router hijacking to breach accounts,” said Black Lotus security engineer Ryan English.

Microsoft’s blog notes the technique enabled “post‑compromise adversary‑in‑the‑middle (AiTM) attacks on TLS connections to Outlook on the web.” The U.K.’s NCSC has issued an advisory warning of similar DNS‑based intrusions (Reuters).

U.S. regulators responded by tightening certification rules for consumer‑grade routers, effectively banning foreign‑made models from future approval (AP News). The move aims to curb the “severe cybersecurity risk” posed by insecure edge devices.

Analysis by: Kaelen Frost
Lead Cybersecurity Analyst
Global Data Feed

More from this Intel

Vectra AI Unveils Ascent to Counter AI-Driven Attacks

Vectra AI Unveils Ascent to Counter AI-Driven Attacks

Sep 20, 2026
Google Infiltrated TeamPCP: Inside the Undercover Operation that Stopped a Massive Supply‑Chain Attack

Google Infiltrated TeamPCP: Inside the Undercover Operation that Stopped a...

Sep 20, 2026
Gyazo data breach leaks 23.6 million accounts – massive server flaw exposed

Gyazo data breach leaks 23.6 million accounts – massive server...

Sep 19, 2026
Microsoft security patches shatter record with 974 fixes in September

Microsoft security patches shatter record with 974 fixes in September

Sep 19, 2026
Linux kernel exploit exposes four local‑root flaws, patches urged

Linux kernel exploit exposes four local‑root flaws, patches urged

Sep 18, 2026
Microsoft patches bug behind ‘Defender Antivirus turned off alerts’

Microsoft patches bug behind ‘Defender Antivirus turned off alerts’

Sep 18, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.