Logo
News Ababil
Explore
SYS_NODE: ONLINE // Cyber Security

Russia Router Hack Exposes Microsoft Office Tokens on 18,000 Networks

DECRYPTED BY: Mia Sterling | TIMESTAMP: 2026-04-10 T 09:26:27 Z | [ 2 MIN READ ]
Russia Router Hack Exposes Microsoft Office Tokens on 18,000 Networks
2 Min Read
Share

Security analysts have confirmed a massive Russia router hack that silently harvests Microsoft Office authentication tokens by compromising outdated SOHO routers. At the heart of the operation is a DNS‑hijack that redirects traffic to servers controlled by the GRU‑linked group known as ForestĀ Blizzard.

How the Russia router hack manipulates DNS to steal tokens

Researchers at Black Lotus Labs discovered that the attackers target legacy Mikrotik and TP‑Link devices, many of which are no longer supported. By exploiting public CVEs they change the routers’ DNS settings, pointing users to malicious resolvers. Once in place, the compromised DNS forwards every OAuth token—issued after multi‑factor authentication—to the attackers’ infrastructure.

“They didn’t need malware; they used old‑school DNS hijacking to pull tokens at scale,” said Black Lotus security engineer Ryan English.

The campaign peaked in December 2025, ensnaring ↓ 18,000 routers and ↓ 5,000 consumer devices, according to Microsoft’s own briefing. The victims span government ministries, law‑enforcement agencies, and third‑party email providers across more than 200 organizations.

Why the attack evades traditional defenses

Because the token exchange occurs after the user has already completed multi‑factor authentication, conventional phishing alerts miss the breach entirely. The attackers operate a man‑in‑the‑middle (AiTM) layer on TLS connections, effectively decrypting Outlook‑web traffic without dropping any malicious payload.

Microsoft labels the technique ā€œDNS hijacking to support post‑compromise AiTM attacksā€ and notes it as the first large‑scale use of this method by ForestĀ Blizzard. The group swiftly shifted tactics after an August 2025 NCSC advisory, abandoning malware‑laden routers for pure DNS manipulation.

In response, the U.S. FCC announced a sweeping ban on certifying foreign‑made consumer routers, warning that such hardware presents a “severe cybersecurity risk” capable of disrupting critical infrastructure. The policy allows conditional approvals only through the Department of Homeland Security or the Department of Defense.

For further details see Reuters and AP News.

Analysis by: Mia Sterling
Freelance Intelligence Contributor
(Note: Mia Sterling is covering this desk while Nova Stirling is on special assignment.)
Global Data Feed

More from this Intel

Dysphoria botnet hijacks 200,000 devices, fuels global DDoS surge

Dysphoria botnet hijacks 200,000 devices, fuels global DDoS surge

Jul 27, 2026
Malvertising Campaign SourTrade Forces Browsers to Assemble Malware On‑The‑Fly

Malvertising Campaign SourTrade Forces Browsers to Assemble Malware On‑The‑Fly

Jul 27, 2026
LG Bans Residential Proxy Apps on Its Smart TVs

LG Bans Residential Proxy Apps on Its Smart TVs

Jul 27, 2026
Social media misinformation model maps user‑driven spread

Social media misinformation model maps user‑driven spread

Jul 25, 2026
CISOs vs. Boards: Bridging the Security Communication Gap

CISOs vs. Boards: Bridging the Security Communication Gap

Jul 25, 2026
What the CISA GitHub Leak Reveals About Government Secret Management

What the CISA GitHub Leak Reveals About Government Secret Management

Jul 23, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.