Logo
News Ababil
Explore
Global Intel (English)
Global Intel (English)VOICE
Bengali (বাংলা)
Spanish (Español)VOICE
French (Français)VOICE
German (Deutsch)
Arabic (العربية)
Hindi (हिन्दी)VOICE
Chinese (中文)
Japanese (日本語)
Russian (Русский)
SYS_NODE: ONLINE // Cyber Security

Russia Router Hack Exposes Microsoft Office Tokens on 18,000 Networks

DECRYPTED BY: Mia Sterling | TIMESTAMP: 2026-04-10 T 09:26:27 Z | [ 2 MIN READ ]
Russia Router Hack Exposes Microsoft Office Tokens on 18,000 Networks
2 Min Read
Share

Security analysts have confirmed a massive Russia router hack that silently harvests Microsoft Office authentication tokens by compromising outdated SOHO routers. At the heart of the operation is a DNS‑hijack that redirects traffic to servers controlled by the GRU‑linked group known as Forest Blizzard.

How the Russia router hack manipulates DNS to steal tokens

Researchers at Black Lotus Labs discovered that the attackers target legacy Mikrotik and TP‑Link devices, many of which are no longer supported. By exploiting public CVEs they change the routers’ DNS settings, pointing users to malicious resolvers. Once in place, the compromised DNS forwards every OAuth token—issued after multi‑factor authentication—to the attackers’ infrastructure.

“They didn’t need malware; they used old‑school DNS hijacking to pull tokens at scale,” said Black Lotus security engineer Ryan English.

The campaign peaked in December 2025, ensnaring ↓ 18,000 routers and ↓ 5,000 consumer devices, according to Microsoft’s own briefing. The victims span government ministries, law‑enforcement agencies, and third‑party email providers across more than 200 organizations.

Why the attack evades traditional defenses

Because the token exchange occurs after the user has already completed multi‑factor authentication, conventional phishing alerts miss the breach entirely. The attackers operate a man‑in‑the‑middle (AiTM) layer on TLS connections, effectively decrypting Outlook‑web traffic without dropping any malicious payload.

Microsoft labels the technique “DNS hijacking to support post‑compromise AiTM attacks” and notes it as the first large‑scale use of this method by Forest Blizzard. The group swiftly shifted tactics after an August 2025 NCSC advisory, abandoning malware‑laden routers for pure DNS manipulation.

In response, the U.S. FCC announced a sweeping ban on certifying foreign‑made consumer routers, warning that such hardware presents a “severe cybersecurity risk” capable of disrupting critical infrastructure. The policy allows conditional approvals only through the Department of Homeland Security or the Department of Defense.

For further details see Reuters and AP News.

Analysis by: Mia Sterling
Freelance Intelligence Contributor
(Note: Mia Sterling is covering this desk while Nova Stirling is on special assignment.)
Global Data Feed

More from this Intel

Vectra AI Unveils Ascent to Counter AI-Driven Attacks

Vectra AI Unveils Ascent to Counter AI-Driven Attacks

Sep 20, 2026
Google Infiltrated TeamPCP: Inside the Undercover Operation that Stopped a Massive Supply‑Chain Attack

Google Infiltrated TeamPCP: Inside the Undercover Operation that Stopped a...

Sep 20, 2026
Gyazo data breach leaks 23.6 million accounts – massive server flaw exposed

Gyazo data breach leaks 23.6 million accounts – massive server...

Sep 19, 2026
Microsoft security patches shatter record with 974 fixes in September

Microsoft security patches shatter record with 974 fixes in September

Sep 19, 2026
Linux kernel exploit exposes four local‑root flaws, patches urged

Linux kernel exploit exposes four local‑root flaws, patches urged

Sep 18, 2026
Microsoft patches bug behind ‘Defender Antivirus turned off alerts’

Microsoft patches bug behind ‘Defender Antivirus turned off alerts’

Sep 18, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.