News Ababil.
Explore
SYS_NODE: ONLINE // Cyber Security

Russia Hacked Routers to Harvest Microsoft Office Tokens – Inside the Massive DNS Hijack

DECRYPTED BY: Kaelen Frost | TIMESTAMP: 2026-05-03 T 20:23:09 Z | [ 2 MIN READ ]
Russia Hacked Routers to Harvest Microsoft Office Tokens – Inside the Massive DNS Hijack
2 Min Read
Share

Russia hacked routers to siphon Microsoft Office OAuth tokens from thousands of users, security analysts reported.

How the DNS hijack unfolded

Researchers at Black Lotus Labs, the security arm of Lumen, discovered that the campaign peaked in December 2025, compromising ↓ 18,000 aging Mikrotik and TP‑Link devices. By exploiting unpatched DNS settings, the attackers redirected queries to servers they controlled, allowing a silent man‑in‑the‑middle grab of authentication tokens.

The operation, attributed to the GRU‑linked group known as Forest Blizzard (aka APT28 or Fancy Bear), required no malware drops. Once a router’s DNS was altered, every workstation on the local subnet automatically sent token requests through the hostile resolver, handing the adversary ↑ 5,000 consumer devices and over 200 enterprises full‑account access.

“They didn’t need a fancy payload; they used old‑school router hijacking to breach accounts,” said Black Lotus security engineer Ryan English.

Microsoft’s blog notes the technique enabled “post‑compromise adversary‑in‑the‑middle (AiTM) attacks on TLS connections to Outlook on the web.” The U.K.’s NCSC has issued an advisory warning of similar DNS‑based intrusions (Reuters).

U.S. regulators responded by tightening certification rules for consumer‑grade routers, effectively banning foreign‑made models from future approval (AP News). The move aims to curb the “severe cybersecurity risk” posed by insecure edge devices.

Analysis by: Kaelen Frost
Lead Cybersecurity Analyst
Global Data Feed

More from this Intel

Microsoft Patch Tuesday April 2026: 167 Fixes, Zero‑Day Threats and AI‑Driven Surge

Microsoft Patch Tuesday April 2026: 167 Fixes, Zero‑Day Threats and...

May 02, 2026
Scattered Spider guilty plea: UK hacker Tylerb admits $8 million crypto theft

Scattered Spider guilty plea: UK hacker Tylerb admits $8 million crypto...

May 02, 2026
Christian Phone Network Launches with Mandatory Porn and Gender Content Blocks

Christian Phone Network Launches with Mandatory Porn and Gender Content...

May 01, 2026
PyTorch Lightning Supply Chain Attack Unveils Credential‑Theft Malware

PyTorch Lightning Supply Chain Attack Unveils Credential‑Theft Malware

May 01, 2026
Inside the Botnet: How DDoS attacks on Brazilian ISPs Were Fueled by a Supposed Anti‑DDoS Firm

Inside the Botnet: How DDoS attacks on Brazilian ISPs Were...

May 01, 2026
Jamie Dimon Flags Cyber Risk as New Top Threat to Global Economy

Jamie Dimon Flags Cyber Risk as New Top Threat to...

Apr 30, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.