Logo
News Ababil
Explore
SYS_NODE: ONLINE // Cyber Security

Russia Router Hack Exposes Microsoft Office Tokens on 18,000 Networks

DECRYPTED BY: Mia Sterling | TIMESTAMP: 2026-04-10 T 09:26:27 Z | [ 2 MIN READ ]
Russia Router Hack Exposes Microsoft Office Tokens on 18,000 Networks
2 Min Read
Share

Security analysts have confirmed a massive Russia router hack that silently harvests Microsoft Office authentication tokens by compromising outdated SOHO routers. At the heart of the operation is a DNS‑hijack that redirects traffic to servers controlled by the GRU‑linked group known as ForestĀ Blizzard.

How the Russia router hack manipulates DNS to steal tokens

Researchers at Black Lotus Labs discovered that the attackers target legacy Mikrotik and TP‑Link devices, many of which are no longer supported. By exploiting public CVEs they change the routers’ DNS settings, pointing users to malicious resolvers. Once in place, the compromised DNS forwards every OAuth token—issued after multi‑factor authentication—to the attackers’ infrastructure.

“They didn’t need malware; they used old‑school DNS hijacking to pull tokens at scale,” said Black Lotus security engineer Ryan English.

The campaign peaked in December 2025, ensnaring ↓ 18,000 routers and ↓ 5,000 consumer devices, according to Microsoft’s own briefing. The victims span government ministries, law‑enforcement agencies, and third‑party email providers across more than 200 organizations.

Why the attack evades traditional defenses

Because the token exchange occurs after the user has already completed multi‑factor authentication, conventional phishing alerts miss the breach entirely. The attackers operate a man‑in‑the‑middle (AiTM) layer on TLS connections, effectively decrypting Outlook‑web traffic without dropping any malicious payload.

Microsoft labels the technique ā€œDNS hijacking to support post‑compromise AiTM attacksā€ and notes it as the first large‑scale use of this method by ForestĀ Blizzard. The group swiftly shifted tactics after an August 2025 NCSC advisory, abandoning malware‑laden routers for pure DNS manipulation.

In response, the U.S. FCC announced a sweeping ban on certifying foreign‑made consumer routers, warning that such hardware presents a “severe cybersecurity risk” capable of disrupting critical infrastructure. The policy allows conditional approvals only through the Department of Homeland Security or the Department of Defense.

For further details see Reuters and AP News.

Analysis by: Mia Sterling
Freelance Intelligence Contributor
(Note: Mia Sterling is covering this desk while Nova Stirling is on special assignment.)
Global Data Feed

More from this Intel

News

Shield Your Devices: The Best Antivirus Software 2026 Reviewed

Aug 13, 2026
Hackers Exploit Adobe Commerce Vulnerability to Hijack Customer Accounts

Hackers Exploit Adobe Commerce Vulnerability to Hijack Customer Accounts

Aug 13, 2026
StormEncryptor ransomware Emerges: China‑Linked Hackers Target N‑central Vulnerability

StormEncryptor ransomware Emerges: China‑Linked Hackers Target N‑central Vulnerability

Aug 11, 2026
Water System Attacks Surge Across U.S., Iran Suspected

Water System Attacks Surge Across U.S., Iran Suspected

Aug 11, 2026
Evolving Threat: StormEncryptor ransomware Targets Mid‑Size Firms After Medusa Split

Evolving Threat: StormEncryptor ransomware Targets Mid‑Size Firms After Medusa Split

Aug 11, 2026
GhostJacking Reveals Critical Gaps in AI Identity Governance

GhostJacking Reveals Critical Gaps in AI Identity Governance

Aug 11, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.