INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Russia's Forest Blizzard Exploits SOHO Routers
| 2026-04-09 01:00 CRITICAL HIGHExecutive Summary AI-generated
Russia's Forest Blizzard, a sophisticated threat group known as APT28 or Fancy Bear, has been quietly infiltrating the internet traffic of targets across the globe for over a year now. Using old bugs in unloved and Internet-exposed small office/home office (SOHO) routers, they have successfully snuck into networks to steal sensitive information from organizations such as ministries of foreign affairs and national law-enforcement bodies worldwide. The group's ability to evade detection has been impressive, with victims including the US Justice Department's Operation Masquerade aimed at disrupting their campaign. Despite this, Forest Blizzard remains a persistent threat, exploiting vulnerabilities in edge devices like MikroTik and TP-Link routers to direct traffic through malicious virtual private servers.
Technical Mitigations AI-generated
• The Russian Main Directorate of the General Staff of the Armed Forces (GRU) has been using old bugs in edge devices, primarily MikroTik and TP-Link routers, to intercept Internet traffic from targets worldwide.
• APT28's subgroup Storm-2754 exploits these vulnerabilities by reconfiguring compromised routers to direct traffic through malicious virtual private servers (VPS).
• The attackers use email spying techniques, targeting known vulnerabilities like CVE-2023-50224 in MikroTik and TP-Link devices to gain access to router interfaces.
• One of the most significant technical mitigations is using endpoint detection and response (EDR) tools or uploading data to VirusTotal to scan for malware on compromised routers.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation MasqueradeOperation Masquerade
APT28APT28
SofacySofacySednitSednit
CVE-2023-50224CVE-2023-50224
Target & Sectors
LATAM
LATAM
AFRICA
AFRICA
DACH
DACH
APAC
APAC
NORTH_AMERICA
NORTH_AMERICA
EUROPE
EUROPE
Incident Timeline
April 2018
Threat actors used DNS hijacking to target SOHO routers in an April 2018 campaign attributed to APT28.
Click on any entity below to view its context and source!
threat_actor
APT28
The NCSC has previously attributed activity to APT28, including the
2015 cyber-attacks against the German parliament
and
an attempted attack against the Organisation for the Prohibition of Chemical Weapons
(OPCW) in April 2018.
target_region
Germany
The NCSC has previously attributed activity to APT28, including the
2015 cyber-attacks against the German parliament
and
an attempted attack against the Organisation for the Prohibition of Chemical Weapons
(OPCW) in April 2018.
organisation
OPCW
The NCSC has previously attributed activity to APT28, including the
2015 cyber-attacks against the German parliament
and
an attempted attack against the Organisation for the Prohibition of Chemical Weapons
(OPCW) in April 2018.
2025/04/09
Black Lotus Labs identified a compromised SOHO router associated with the government of Afghanistan in May 2023.
Click on any entity below to view its context and source!
source_region
Afghanistan
Black Lotus Labs cited May of last year, at which point it identified a compromised router associated with the government of Afghanistan.
at least May 2025
Threat actors used old bugs in MikroTik and TP-Link edge devices to intercept Internet traffic at middle- and high-value organizations worldwide.
Click on any entity below to view its context and source!
source_region
Russian Federation
Since at least May 2025, if not 2024, the Russian Main Directorate of the General Staff of the Armed Forces (GRU)-backed threat group has been intercepting Internet traffic at middle- and high-value organizations worldwide simply by exploiting old bugs in edge devices — primarily, but not exclusively, MikroTik and TP-Link routers — and reconfiguring them to direct traffic through malicious virtual private servers (VPS).
organisation
the Russian Main Directorate
Since at least May 2025, if not 2024, the Russian Main Directorate of the General Staff of the Armed Forces (GRU)-backed threat group has been intercepting Internet traffic at middle- and high-value organizations worldwide simply by exploiting old bugs in edge devices — primarily, but not exclusively, MikroTik and TP-Link routers — and reconfiguring them to direct traffic through malicious virtual private servers (VPS).
organisation
the Armed Forces
Since at least May 2025, if not 2024, the Russian Main Directorate of the General Staff of the Armed Forces (GRU)-backed threat group has been intercepting Internet traffic at middle- and high-value organizations worldwide simply by exploiting old bugs in edge devices — primarily, but not exclusively, MikroTik and TP-Link routers — and reconfiguring them to direct traffic through malicious virtual private servers (VPS).
organisation
MikroTik
Since at least May 2025, if not 2024, the Russian Main Directorate of the General Staff of the Armed Forces (GRU)-backed threat group has been intercepting Internet traffic at middle- and high-value organizations worldwide simply by exploiting old bugs in edge devices — primarily, but not exclusively, MikroTik and TP-Link routers — and reconfiguring them to direct traffic through malicious virtual private servers (VPS).
organisation
VPS
Since at least May 2025, if not 2024, the Russian Main Directorate of the General Staff of the Armed Forces (GRU)-backed threat group has been intercepting Internet traffic at middle- and high-value organizations worldwide simply by exploiting old bugs in edge devices — primarily, but not exclusively, MikroTik and TP-Link routers — and reconfiguring them to direct traffic through malicious virtual private servers (VPS).
at least May 2025
The Russia-linked threat actor APT28 (aka Forest Blizzard) has been linked to a cyber espionage campaign targeting insecure MikroTik and TP-Link routers since at least May 2025.
Click on any entity below to view its context and source!
source_region
Russian Federation
The Russia-linked threat actor known as
APT28
(aka Forest Blizzard) has been linked to a new campaign that has compromised insecure MikroTik and TP-Link routers and modified their settings to turn them into malicious infrastructure under their control as part of a cyber espionage campaign since at least May 2025.
tactic
Espionage
The Russia-linked threat actor known as
APT28
(aka Forest Blizzard) has been linked to a new campaign that has compromised insecure MikroTik and TP-Link routers and modified their settings to turn them into malicious infrastructure under their control as part of a cyber espionage campaign since at least May 2025.
threat_actor
APT28
The Russia-linked threat actor known as
APT28
(aka Forest Blizzard) has been linked to a new campaign that has compromised insecure MikroTik and TP-Link routers and modified their settings to turn them into malicious infrastructure under their control as part of a cyber espionage campaign since at least May 2025.
organisation
MikroTik
The Russia-linked threat actor known as
APT28
(aka Forest Blizzard) has been linked to a new campaign that has compromised insecure MikroTik and TP-Link routers and modified their settings to turn them into malicious infrastructure under their control as part of a cyber espionage campaign since at least May 2025.
May 2025
Threat actors used a previously unknown vulnerability in SOHO routers to gain initial access and then exploited it to launch widespread attacks.
Aug. 6, 2025
Threat actors used APT28 malware to target SOHO routers in a DNS hijacking campaign.
Click on any entity below to view its context and source!
threat_actor
APT28
On Aug. 6, 2025, the United Kingdom's National Cyber Security Centre (NCSC) published a report on "Authentic Antics," about an APT28 malware tool designed to nab Microsoft Office credentials and tokens.
target_region
United Kingdom
On Aug. 6, 2025, the United Kingdom's National Cyber Security Centre (NCSC) published a report on "Authentic Antics," about an APT28 malware tool designed to nab Microsoft Office credentials and tokens.
organisation
Microsoft Office
On Aug. 6, 2025, the United Kingdom's National Cyber Security Centre (NCSC) published a report on "Authentic Antics," about an APT28 malware tool designed to nab Microsoft Office credentials and tokens.
organisation
National Cyber Security Centre
On Aug. 6, 2025, the United Kingdom's National Cyber Security Centre (NCSC) published a report on "Authentic Antics," about an APT28 malware tool designed to nab Microsoft Office credentials and tokens.
organisation
NCSC
On Aug. 6, 2025, the United Kingdom's National Cyber Security Centre (NCSC) published a report on "Authentic Antics," about an APT28 malware tool designed to nab Microsoft Office credentials and tokens.
at least August 2025
Threat actors used APT28 to compromise SOHO routers.
Click on any entity below to view its context and source!
threat_actor
APT28
In
a separate report
, also published on April 7, Microsoft Threat Intelligence said APT28 and and its sub-group tracked as Storm-2754, started compromising VPS servers to exploit small office/home office (SOHO) routers "since at least August 2025.
attribution
Storm-2754
In
a separate report
, also published on April 7, Microsoft Threat Intelligence said APT28 and and its sub-group tracked as Storm-2754, started compromising VPS servers to exploit small office/home office (SOHO) routers "since at least August 2025.
attribution
Microsoft Threat Intelligence
In
a separate report
, also published on April 7, Microsoft Threat Intelligence said APT28 and and its sub-group tracked as Storm-2754, started compromising VPS servers to exploit small office/home office (SOHO) routers "since at least August 2025.
attribution
SOHO
In
a separate report
, also published on April 7, Microsoft Threat Intelligence said APT28 and and its sub-group tracked as Storm-2754, started compromising VPS servers to exploit small office/home office (SOHO) routers "since at least August 2025.
December 2025
Threat actors used compromised SOHO routers to target the Lazarus Group in a DNS hijacking campaign.
Click on any entity below to view its context and source!
organisation
IP
At its peak in December 2025, Black Lotus Labs identified 18,000 unique IP addresses across at least 120 countries that were communicating with the attackers' infrastructure.
At its peak in December 2025, more than 18,000 unique IP addresses from no less than 120 countries were found communicating with APT28 infrastructure.
infrastructure
18,000 unique IP addresses
At its peak in December 2025, Black Lotus Labs identified 18,000 unique IP addresses across at least 120 countries that were communicating with the attackers' infrastructure.
At its peak in December 2025, more than 18,000 unique IP addresses from no less than 120 countries were found communicating with APT28 infrastructure.
general_metric
120 countries
At its peak in December 2025, Black Lotus Labs identified 18,000 unique IP addresses across at least 120 countries that were communicating with the attackers' infrastructure.
At its peak in December 2025, more than 18,000 unique IP addresses from no less than 120 countries were found communicating with APT28 infrastructure.
threat_actor
APT28
At its peak in December 2025, more than 18,000 unique IP addresses from no less than 120 countries were found communicating with APT28 infrastructure.
April 7
Threat actors used SOHO routers to launch DNS hijacking campaigns attributed to APT28.
Click on any entity below to view its context and source!
target_region
United States
Related:
Iran Hacktivists Make Noise but Have Little Impact on War
On April 7, the US Justice Department (DoJ) announced a large-scale and court-ordered disruption effort called "
Operation Masquerade
," aimed at pushing back the portion of APT28's campaign that's affected the US.
threat_actor
APT28
Related:
Iran Hacktivists Make Noise but Have Little Impact on War
On April 7, the US Justice Department (DoJ) announced a large-scale and court-ordered disruption effort called "
Operation Masquerade
," aimed at pushing back the portion of APT28's campaign that's affected the US.
In
a new advisory
published on April 7, the UK’s National Cyber Security Centre (NCSC) said it detected two new malicious campaigns it attributed to
APT28
.
In
a separate report
, also published on April 7, Microsoft Threat Intelligence said APT28 and and its sub-group tracked as Storm-2754, started compromising VPS servers to exploit small office/home office (SOHO) routers "since at least August 2025.
target_region
Iran, Islamic Republic of
Related:
Iran Hacktivists Make Noise but Have Little Impact on War
On April 7, the US Justice Department (DoJ) announced a large-scale and court-ordered disruption effort called "
Operation Masquerade
," aimed at pushing back the portion of APT28's campaign that's affected the US.
campaign
Operation Masquerade
Related:
Iran Hacktivists Make Noise but Have Little Impact on War
On April 7, the US Justice Department (DoJ) announced a large-scale and court-ordered disruption effort called "
Operation Masquerade
," aimed at pushing back the portion of APT28's campaign that's affected the US.
organisation
the US Justice Department
Related:
Iran Hacktivists Make Noise but Have Little Impact on War
On April 7, the US Justice Department (DoJ) announced a large-scale and court-ordered disruption effort called "
Operation Masquerade
," aimed at pushing back the portion of APT28's campaign that's affected the US.
organisation
DoJ
Related:
Iran Hacktivists Make Noise but Have Little Impact on War
On April 7, the US Justice Department (DoJ) announced a large-scale and court-ordered disruption effort called "
Operation Masquerade
," aimed at pushing back the portion of APT28's campaign that's affected the US.
target_region
United Kingdom
In
a new advisory
published on April 7, the UK’s National Cyber Security Centre (NCSC) said it detected two new malicious campaigns it attributed to
APT28
.
organisation
National Cyber Security Centre
In
a new advisory
published on April 7, the UK’s National Cyber Security Centre (NCSC) said it detected two new malicious campaigns it attributed to
APT28
.
organisation
NCSC
In
a new advisory
published on April 7, the UK’s National Cyber Security Centre (NCSC) said it detected two new malicious campaigns it attributed to
APT28
.
attribution
Storm-2754
In
a separate report
, also published on April 7, Microsoft Threat Intelligence said APT28 and and its sub-group tracked as Storm-2754, started compromising VPS servers to exploit small office/home office (SOHO) routers "since at least August 2025.
attribution
Microsoft Threat Intelligence
In
a separate report
, also published on April 7, Microsoft Threat Intelligence said APT28 and and its sub-group tracked as Storm-2754, started compromising VPS servers to exploit small office/home office (SOHO) routers "since at least August 2025.
attribution
SOHO
In
a separate report
, also published on April 7, Microsoft Threat Intelligence said APT28 and and its sub-group tracked as Storm-2754, started compromising VPS servers to exploit small office/home office (SOHO) routers "since at least August 2025.
2026/04/09
Forest Blizzard used DNS hijacking and AitM activity to conduct espionage against SOHO routers in a campaign targeting 23 US states, with the infrastructure associated with the campaign disrupted as part of a joint operation.
Click on any entity below to view its context and source!
organisation
Forest Blizzard Nabs Rafts
Russia's Forest Blizzard Nabs Rafts of Logins via SOHO Routers.
organisation
SOHO
Russia's Forest Blizzard Nabs Rafts of Logins via SOHO Routers.
The large-scale exploitation campaign has been
codenamed
FrostArmada
by Lumen's Black Lotus Labs, with Microsoft
describing
it as an effort to exploit vulnerable home and small office (SOHO) internet devices to hijack DNS traffic and enable passive collection of network data.
"
First Activity Cluster Targets TP-Link Routers
In the first activity cluster identified by the British cybersecurity agency, the dynamic host configuration protocol (DHCP) DNS settings of compromised SOHO routers,
mostly TP-Link routers
, were modified to include actor-owned IP addresses.
threat_actor
APT28
But Russia's
APT28
(aka Fancy Bear or Forest Blizzard, among other monikers) and its subgroup Storm-2754 have proven that that simply isn't the case.
The UK government associates APT28 “almost certainly” to the Russian General Staff Main Intelligence Directorate’s (GRU) 85th Main Special Service Centre (GTsSS) Military Intelligence Unit 26165, is known under many other names, including
Fancy Bear
, Forest Blizzard, Strontium, the Sednit Gang, and Sofacy.
Russian Cyber Espionage Via SOHO Routers
APT28's game is email spying.
Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking Campaign.
Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns.
Russian hacking group APT28 has been exploiting vulnerable internet routers to redirect traffic through attacker-controlled servers and steal credentials from targeted organizations, the UK government has warned.
Related:
SideWinder Espionage Campaign Expands Across Southeast Asia
Researchers differ on when exactly APT28 started doing all this.
Related:
EU Sanctions Companies in China, Iran for Cyberattacks
In this latest campaign, APT28's path to email compromise primarily went through
SOHO routers
from MikroTik and TP-Link, and in fewer cases firewall products from Nethesis and Fortinet.
Whenever someone using the router requested to visit a website, that request would pass through APT28's infrastructure.
If the website was one that APT28 was interested in — like Microsoft Outlook on the Web — it would proxy that request, stealing the victim's credentials as they visited that online service.
APT28 might have been deterred, if it weren't so utterly prepared.
"It seems odd that some of these governments that were targets [of APT28] would be using small office/home office routers," he admits, but adds that "it's a question of economics, convenience, and access.
"
For Adamitis, APT28's campaign is about a much more significant and intractable issue with one of the Internet's foundational systems:
DNS
— a common target for APT28.
"[But APT28] is modifying all that in the back end.
APT28 is said to have exploited TP-Link WR841N routers for its DNS poisoning operations by likely taking advantage of
CVE-2023-50224
(CVSS score: 6.5), an authentication bypass vulnerability that could be used to extract stored credentials via specially crafted HTTP GET requests.
The Microsoft Threat Intelligence team, in its analysis of the campaign, attributed the activity to APT28 and its sub-group tracked as Storm-2754.
At a high level, the attack chain involves APT28 gaining remote administrative access to SOHO devices and changing default network configurations to use DNS resolvers under its control.
Both campaigns are linked to a list of virtual private servers (VPS), which have been actively modified by APT28 since 2024 to operate as malicious domain name system (DNS) servers.
The NCSC assessed that the initial DNS hijacking operations are “opportunistic in nature,” meaning that the APT28 hackers likely use this method to first gain visibility of a large pool of candidates and then filter down users at each stage in the exploitation chain to triage for “victims of likely intelligence value.”
These settings were subsequently inherited by downstream devices, for example laptops and phones, leading requests matching APT28’s targeting criteria to be resolved by the malicious DNS servers to IP addresses owned by the threat actor.
The APT28 hackers would then attempt to conduct
adversary-in-the-middle (AitM) attacks
against follow-on connections, including user browser sessions and desktop applications, likely to harvest passwords, OAuth tokens and other credentials for web and email related services.
NCSC Recommendations to Stop APT28’s Credential Theft
Forest Blizzard, also known as APT28 and Fancy Bear, exploited known vulnerabilities to steal credentials for
thousands of TP-Link routers
globally.
The U.K.’s NCSC on Tuesday published details about
APT28’s DNS hijacking campaign
, including indicators of compromise.
organisation
Storm-2754
But Russia's
APT28
(aka Fancy Bear or Forest Blizzard, among other monikers) and its subgroup Storm-2754 have proven that that simply isn't the case.
organisation
DoJ
Per the DoJ, threat actors affiliated with Military Unit 26165 of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU) have exploited known security vulnerabilities to steal credentials for thousands of TP-Link routers worldwide since at least 2024, using them to redirect DNS requests to GRU-controlled servers.
organisation
Military Unit
Per the DoJ, threat actors affiliated with Military Unit 26165 of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU) have exploited known security vulnerabilities to steal credentials for thousands of TP-Link routers worldwide since at least 2024, using them to redirect DNS requests to GRU-controlled servers.
organisation
the Main Directorate of the General Staff
Per the DoJ, threat actors affiliated with Military Unit 26165 of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU) have exploited known security vulnerabilities to steal credentials for thousands of TP-Link routers worldwide since at least 2024, using them to redirect DNS requests to GRU-controlled servers.
organisation
the Armed Forces of the Russian Federation
Per the DoJ, threat actors affiliated with Military Unit 26165 of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU) have exploited known security vulnerabilities to steal credentials for thousands of TP-Link routers worldwide since at least 2024, using them to redirect DNS requests to GRU-controlled servers.
organisation
Lumen
The large-scale exploitation campaign has been
codenamed
FrostArmada
by Lumen's Black Lotus Labs, with Microsoft
describing
it as an effort to exploit vulnerable home and small office (SOHO) internet devices to hijack DNS traffic and enable passive collection of network data.
Lumen said it observed widespread router exploitation and DNS redirection beginning in August, the day after the United Kingdom’s National Cyber Security Centre published a
malware analysis report
about a tool used to steal Microsoft Office credentials.
According to researchers with Lumen's Black Lotus Labs and Microsoft, this low-effort campaign has empowered the threat actor to
sniff Web traffic with aplomb
and
steal credentials for email and Web services
on an ongoing basis.
organisation
Black Lotus Labs
The large-scale exploitation campaign has been
codenamed
FrostArmada
by Lumen's Black Lotus Labs, with Microsoft
describing
it as an effort to exploit vulnerable home and small office (SOHO) internet devices to hijack DNS traffic and enable passive collection of network data.
According to researchers with Lumen's Black Lotus Labs and Microsoft, this low-effort campaign has empowered the threat actor to
sniff Web traffic with aplomb
and
steal credentials for email and Web services
on an ongoing basis.
“The campaign has ceased,” Danny Adamitis, distinguished engineer at Black Lotus Labs, told CyberScoop.
organisation
Microsoft
The large-scale exploitation campaign has been
codenamed
FrostArmada
by Lumen's Black Lotus Labs, with Microsoft
describing
it as an effort to exploit vulnerable home and small office (SOHO) internet devices to hijack DNS traffic and enable passive collection of network data.
According to researchers with Lumen's Black Lotus Labs and Microsoft, this low-effort campaign has empowered the threat actor to
sniff Web traffic with aplomb
and
steal credentials for email and Web services
on an ongoing basis.
This allowed attackers to intercept passwords, OAuth tokens, credentials for Microsoft accounts, and other services and cloud-hosted content.
organisation
DNS
The large-scale exploitation campaign has been
codenamed
FrostArmada
by Lumen's Black Lotus Labs, with Microsoft
describing
it as an effort to exploit vulnerable home and small office (SOHO) internet devices to hijack DNS traffic and enable passive collection of network data.
Both campaigns are linked to a list of virtual private servers (VPS), which have been actively modified by APT28 since 2024 to operate as malicious domain name system (DNS) servers.
Lumen said it observed widespread router exploitation and DNS redirection beginning in August, the day after the United Kingdom’s National Cyber Security Centre published a
malware analysis report
about a tool used to steal Microsoft Office credentials.
This three-year-old vulnerability allowed the attackers to remotely administer routers, and modify their Domain Name System (DNS) settings to route traffic through a VPS they controlled.
organisation
IP
"
First Activity Cluster Targets TP-Link Routers
In the first activity cluster identified by the British cybersecurity agency, the dynamic host configuration protocol (DHCP) DNS settings of compromised SOHO routers,
mostly TP-Link routers
, were modified to include actor-owned IP addresses.
organisation
DHCP
"
First Activity Cluster Targets TP-Link Routers
In the first activity cluster identified by the British cybersecurity agency, the dynamic host configuration protocol (DHCP) DNS settings of compromised SOHO routers,
mostly TP-Link routers
, were modified to include actor-owned IP addresses.
organisation
Global DNS Hijacking Campaign
Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking Campaign.
organisation
UK Security Agency
Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns.
infrastructure
18,000 unique IP addresses
Feds quash widespread Russia-backed espionage network spanning 18,000 devices.
Russian state-sponsored attackers compromised more than 18,000 routers spread across more than 120 countries to gain deeper access to sensitive networks for a large-scale espionage campaign before it was recently neutralized, researchers and authorities said Tuesday.
organisation
Feds
Feds quash widespread Russia-backed espionage network spanning 18,000 devices.
victims
200 impacted organizations
The threat group established an expansive espionage network by intruding systems of
more than 200 organizations
, impacting at least 5,000 consumer devices, Microsoft Threat Intelligence said in a report.
Microsoft identified more than 200 impacted organizations, plus more than 5,000 consumer devices.
The tech giant said it identified more than 200 organizations and 5,000 consumer devices impacted by the threat actor's malicious DNS infrastructure.
infrastructure
5,000 consumer devices
The threat group established an expansive espionage network by intruding systems of
more than 200 organizations
, impacting at least 5,000 consumer devices, Microsoft Threat Intelligence said in a report.
Microsoft identified more than 200 impacted organizations, plus more than 5,000 consumer devices.
The tech giant said it identified more than 200 organizations and 5,000 consumer devices impacted by the threat actor's malicious DNS infrastructure.
organisation
GRU
“GRU actors compromised routers in the U.S. and around the world, hijacking them to conduct espionage.
"For select targets, the GRU's DNS resolvers provided fraudulent DNS records for specific domains that mimicked legitimate services – including Microsoft Outlook Web Access – to facilitate Actor-in-the-Middle attacks against encrypted victim network traffic.
organisation
EU Sanctions Companies
Related:
EU Sanctions Companies in China, Iran for Cyberattacks
In this latest campaign, APT28's path to email compromise primarily went through
SOHO routers
from MikroTik and TP-Link, and in fewer cases firewall products from Nethesis and Fortinet.
organisation
Microsoft Outlook
If the website was one that APT28 was interested in — like Microsoft Outlook on the Web — it would proxy that request, stealing the victim's credentials as they visited that online service.
Some of these domains are associated with Microsoft Outlook on the web.
organisation
CVE-2023-50224
APT28 is said to have exploited TP-Link WR841N routers for its DNS poisoning operations by likely taking advantage of
CVE-2023-50224
(CVSS score: 6.5), an authentication bypass vulnerability that could be used to extract stored credentials via specially crafted HTTP GET requests.
For example, one bug it scanned the Web for was CVE-2023-50224: a medium-severity information disclosure issue affecting TP-Link, which doesn't require authentication to exploit.
One of the router models appearing in this campaign, the TP-Link WR841N, was likely exploited using CVE-2023-50224, a vulnerability that enables an unauthenticated attacker to obtain information such as password credentials via specially crafted HTTP GET requests.
organisation
VPS
Both campaigns are linked to a list of virtual private servers (VPS), which have been actively modified by APT28 since 2024 to operate as malicious domain name system (DNS) servers.
organisation
Credential Theft
NCSC Recommendations to Stop APT28’s Credential Theft
organisation
Operation Masquerade
The law enforcement effort has been codenamed Operation Masquerade.
organisation
Microsoft Office
Lumen said it observed widespread router exploitation and DNS redirection beginning in August, the day after the United Kingdom’s National Cyber Security Centre published a
malware analysis report
about a tool used to steal Microsoft Office credentials.
organisation
National Cyber Security Centre
Lumen said it observed widespread router exploitation and DNS redirection beginning in August, the day after the United Kingdom’s National Cyber Security Centre published a
malware analysis report
about a tool used to steal Microsoft Office credentials.
organisation
CyberScoop
“The campaign has ceased,” Danny Adamitis, distinguished engineer at Black Lotus Labs, told CyberScoop.
organisation
Domain Name System
This three-year-old vulnerability allowed the attackers to remotely administer routers, and modify their Domain Name System (DNS) settings to route traffic through a VPS they controlled.
organisation
EDR
"If you were to have your router getting logged into, even if you were to hypothetically scan it all with an endpoint detection and response (EDR) tool or upload everything to VirusTotal, there is nothing there.
organisation
VirusTotal
"If you were to have your router getting logged into, even if you were to hypothetically scan it all with an endpoint detection and response (EDR) tool or upload everything to VirusTotal, there is nothing there.
organisation
Lumen Technologies
Ryan English, information security engineer at Lumen Technologies, suggests that organizations do their best to move away from SOHO routers, but recognizes the reasons they're so prevalent.
organisation
Google Maps
To demonstrate the point, he draws a parallel with Google Maps.
organisation
Google
When one uses Google Maps, "I just trust that Google can tell me the right way to go, because that's how the system is supposed to work.
organisation
Omdia
Don't miss the latest Dark Reading Confidential podcast,
Security Bosses Are All in on AI: Here's Why,
where Reddit CISO Frederick Lee and Omdia analyst Dave Gruber discuss AI and machine learning in the SOC, how successful deployments have (or haven’t) been, and what the future holds for AI security products.
organisation
SOC
Don't miss the latest Dark Reading Confidential podcast,
Security Bosses Are All in on AI: Here's Why,
where Reddit CISO Frederick Lee and Omdia analyst Dave Gruber discuss AI and machine learning in the SOC, how successful deployments have (or haven’t) been, and what the future holds for AI security products.
organisation
The Hacker News
"Their technique modified DNS settings on compromised routers to hijack local network traffic to capture and exfiltrate authentication credentials," Black Lotus Labs said in a report shared with The Hacker News.
organisation
the U.S. Department of Justice
The infrastructure associated with the campaign has been disrupted and taken offline as part of a joint operation in collaboration with the U.S. Department of Justice, Federal Bureau of Investigation, and other international partners.
organisation
Federal Bureau of Investigation
The infrastructure associated with the campaign has been disrupted and taken offline as part of a joint operation in collaboration with the U.S. Department of Justice, Federal Bureau of Investigation, and other international partners.
organisation
AiTM of Transport Layer Security
The development marks the first time the adversarial collective has been observed using DNS hijacking at scale to support AiTM of Transport Layer Security (TLS) connections after exploiting edge devices, Microsoft added.
organisation
Microsoft Outlook Web Access
"For select targets, the GRU's DNS resolvers provided fraudulent DNS records for specific domains that mimicked legitimate services – including Microsoft Outlook Web Access – to facilitate Actor-in-the-Middle attacks against encrypted victim network traffic.
organisation
AiTM
"Although we have only observed Forest Blizzard utilizing their DNS hijacking campaign for information collection, an attacker could use an AiTM position for additional outcomes, such as malware deployment or denial of service."
organisation
MFA
These include:
Using browse-down architecture to prevent attackers easily gaining privileged access to your most vital assets
Using the latest supported versions, applying security updates promptly, deploying antivirus and regularly scanning to detect known malware threats
Adding applications to an allowlist
Deploying a host-based intrusion detection system
Using multifactor authentication (MFA)
Tactical Metrics
Metrics
infrastructure
Microsoft Office
Affected Product
Click for context!
On Aug. 6, 2025, the United Kingdom's National Cyber Security Centre (NCSC) published a report on "Authentic Antics," about an APT28 malware tool designed to nab Microsoft Office credentials and tokens.
Lumen said it observed widespread router exploitation and DNS redirection beginning in August, the day after the United Kingdom’s National Cyber Security Centre published a
malware analysis report
about a tool used to steal Microsoft Office credentials.
Metrics
infrastructure
18,000
Unique Ip Addresses
At its peak in December 2025, Black Lotus Labs identified 18,000 unique IP addresses across at least 120 countries that were communicating with the attackers' infrastructure.
At its peak in December 2025, more than 18,000 unique IP addresses from no less than 120 countries were found communicating with APT28 infrastructure.
Feds quash widespread Russia-backed espionage network spanning 18,000 devices.
Russian state-sponsored attackers compromised more than 18,000 routers spread across more than 120 countries to gain deeper access to sensitive networks for a large-scale espionage campaign before it was recently neutralized, researchers and authorities said Tuesday.
Metrics
victims
200
Impacted Organizations
Microsoft identified more than 200 impacted organizations, plus more than 5,000 consumer devices.
The tech giant said it identified more than 200 organizations and 5,000 consumer devices impacted by the threat actor's malicious DNS infrastructure.
The threat group established an expansive espionage network by intruding systems of
more than 200 organizations
, impacting at least 5,000 consumer devices, Microsoft Threat Intelligence said in a report.
Metrics
infrastructure
5,000
Consumer Devices
Microsoft identified more than 200 impacted organizations, plus more than 5,000 consumer devices.
The tech giant said it identified more than 200 organizations and 5,000 consumer devices impacted by the threat actor's malicious DNS infrastructure.
The threat group established an expansive espionage network by intruding systems of
more than 200 organizations
, impacting at least 5,000 consumer devices, Microsoft Threat Intelligence said in a report.
Intelligence Sources
The Hacker News
2026-04-07
Infosecurity-Magazine
2026-04-07
Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns
Infosecurity-Magazine
CyberScoop
2026-04-07
Dark Reading
2026-04-09
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Reset / Delete
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-15T07:30
Comprehensive Tactical Telemetry
Highly Correlated Entities
50x
organisation
Identified Entity
Forest Blizzard Nabs Rafts
entity
16x
attribution
Attributing Entity
DoJ
authority
12x
timeline
Temporal Reference
at least May 2025
date
7x
target region
Target Country
Russian Federation
country
4x
source region
Origin Country
Russian Federation
country
4x
target region
Target Region
AFRICA
region
2x
tactic
Cyber Operation Type
Espionage
tactic
2x
tactic
MITRE ATT&CK Technique
T1588.005 - Exploits
technique
2x
source region
Origin Region
AFRICA
region
2x
malware
Malware Payload
Sednit
tool
Contextual Telemetry
Context Block
11 METRICS
general metric
Us States
23
us states
threat actor
APT Group
APT28
actor
campaign
Campaign
Operation Masquerade
operation
infrastructure
Affected Product
Microsoft Office
software
vulnerability
Exploited CVE
CVE-2023-50224
cve
general metric
Cve-2023
50,224
cve-2023
infrastructure
Unique Ip Addresses
18,000
unique ip addresses
general metric
Countries
120
countries
victims
Impacted Organizations
200
impacted organizations
infrastructure
Consumer Devices
5,000
consumer devices
general metric
Score
6
score
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.