Logo
News Ababil
Explore
SYS_NODE: ONLINE // Cyber Security

Russia Hacked Routers: Massive DNS Hijack Steals Microsoft Office Tokens

DECRYPTED BY: Nova Stirling | TIMESTAMP: 2026-04-17 T 15:39:45 Z | [ 2 MIN READ ]
Russia Hacked Routers: Massive DNS Hijack Steals Microsoft Office Tokens
2 Min Read
Share

Security analysts have confirmed that Russia hacked routers to siphon Microsoft Office authentication tokens, exploiting legacy DNS flaws on thousands of devices. The operation, attributed to the GRU‑linked group known as Forest Blizzard (also called APT28 or Fancy Bear), rewired DNS settings on vulnerable SOHO routers, directing traffic to attacker‑controlled servers that harvested OAuth tokens after users logged in.

How the DNS hijack worked

Researchers at Black Lotus Labs discovered that the hackers focused on outdated Mikrotik and TP‑Link units, many of which were past end‑of‑life and missing critical patches. By injecting rogue DNS entries, the compromised routers silently rerouted all internal requests, allowing the adversaries to capture tokens without deploying any malware. The stolen tokens, which are issued after multi‑factor authentication, gave the actors direct access to corporate and government Outlook accounts.

ā€œThey didn’t need a payload; they just twisted the DNS and walked away with credentials,ā€ said Black Lotus security engineer Ryan English.

The campaign peaked in December 2025, ensnaring ↑ 18,000 routers and affecting over ↓ 5,000 consumer devices, according to Microsoft’s disclosure. More than 200 organizations, including foreign ministries and law‑enforcement agencies, were exposed.

Response and policy fallout

In March, the U.S. FCC announced a ban on certifying non‑U.S.‑made consumer routers, citing the ā€œsevere cybersecurity riskā€ posed by foreign hardware. While the policy stops new imports, existing equipment remains in use, prompting calls for rapid firmware updates and network segmentation.

Experts warn that similar DNS‑based man‑in‑the‑middle tactics could reappear if legacy equipment is not retired. The incident underscores the enduring value of simple, low‑tech exploits in state‑sponsored espionage.

For further details, see the Reuters report and Microsoft’s official blog.


Analysis by Nova Stirling (Aerospace & Space Tech Correspondent).

Global Data Feed

More from this Intel

TSN Protocols: Emerging Industrial Protocol Family Threatens OT Security

TSN Protocols: Emerging Industrial Protocol Family Threatens OT Security

Aug 23, 2026
LG residential proxy ban forces smart‑TV app purge

LG residential proxy ban forces smart‑TV app purge

Aug 23, 2026
OWASP AI Skill Risks Highlighted in New Security Blueprint

OWASP AI Skill Risks Highlighted in New Security Blueprint

Aug 23, 2026
Leaked AWS Keys Expose 768 Cloud Accounts – 88% Still Active

Leaked AWS Keys Expose 768 Cloud Accounts – 88% Still...

Aug 22, 2026
RedC2 4.0 Linux Backdoor Unveiled in 14 Trojanized npm Packages

RedC2 4.0 Linux Backdoor Unveiled in 14 Trojanized npm Packages

Aug 22, 2026
Cyber Pros Needed to Defend City Hall – Join the Volunteer Shield

Cyber Pros Needed to Defend City Hall – Join the...

Aug 21, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.