INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Russia's Forest Blizzard Exploits SOHO Routers

| 2026-04-09 01:00 CRITICAL HIGH
Executive Summary AI-generated
Russia's Forest Blizzard, a sophisticated threat group known as APT28 or Fancy Bear, has been quietly infiltrating the internet traffic of targets across the globe for over a year now. Using old bugs in unloved and Internet-exposed small office/home office (SOHO) routers, they have successfully snuck into networks to steal sensitive information from organizations such as ministries of foreign affairs and national law-enforcement bodies worldwide. The group's ability to evade detection has been impressive, with victims including the US Justice Department's Operation Masquerade aimed at disrupting their campaign. Despite this, Forest Blizzard remains a persistent threat, exploiting vulnerabilities in edge devices like MikroTik and TP-Link routers to direct traffic through malicious virtual private servers.
Technical Mitigations AI-generated
• The Russian Main Directorate of the General Staff of the Armed Forces (GRU) has been using old bugs in edge devices, primarily MikroTik and TP-Link routers, to intercept Internet traffic from targets worldwide. • APT28's subgroup Storm-2754 exploits these vulnerabilities by reconfiguring compromised routers to direct traffic through malicious virtual private servers (VPS). • The attackers use email spying techniques, targeting known vulnerabilities like CVE-2023-50224 in MikroTik and TP-Link devices to gain access to router interfaces. • One of the most significant technical mitigations is using endpoint detection and response (EDR) tools or uploading data to VirusTotal to scan for malware on compromised routers.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation MasqueradeOperation Masquerade APT28APT28 SofacySofacySednitSednit CVE-2023-50224CVE-2023-50224
Target & Sectors
LATAM LATAM AFRICA AFRICA DACH DACH APAC APAC NORTH_AMERICA NORTH_AMERICA EUROPE EUROPE
Incident Timeline
‎April 2018
Threat actors used DNS hijacking to target SOHO routers in an April 2018 campaign attributed to APT28.
threat_actor APT28
target_region Germany
organisation OPCW
‎2025/04/09
Black Lotus Labs identified a compromised SOHO router associated with the government of Afghanistan in May 2023.
source_region Afghanistan
‎at least May 2025
Threat actors used old bugs in MikroTik and TP-Link edge devices to intercept Internet traffic at middle- and high-value organizations worldwide.
source_region Russian Federation
organisation the Russian Main Directorate
organisation the Armed Forces
organisation MikroTik
organisation VPS
‎at least May 2025
The Russia-linked threat actor APT28 (aka Forest Blizzard) has been linked to a cyber espionage campaign targeting insecure MikroTik and TP-Link routers since at least May 2025.
source_region Russian Federation
tactic Espionage
threat_actor APT28
organisation MikroTik
‎May 2025
Threat actors used a previously unknown vulnerability in SOHO routers to gain initial access and then exploited it to launch widespread attacks.
‎Aug. 6, 2025
Threat actors used APT28 malware to target SOHO routers in a DNS hijacking campaign.
threat_actor APT28
target_region United Kingdom
organisation Microsoft Office
organisation National Cyber Security Centre
organisation NCSC
‎at least August 2025
Threat actors used APT28 to compromise SOHO routers.
threat_actor APT28
attribution Storm-2754
attribution Microsoft Threat Intelligence
attribution SOHO
‎December 2025
Threat actors used compromised SOHO routers to target the Lazarus Group in a DNS hijacking campaign.
organisation IP
infrastructure 18,000 unique IP addresses
general_metric 120 countries
threat_actor APT28
‎April 7
Threat actors used SOHO routers to launch DNS hijacking campaigns attributed to APT28.
target_region United States
threat_actor APT28
target_region Iran, Islamic Republic of
campaign Operation Masquerade
organisation the US Justice Department
organisation DoJ
target_region United Kingdom
organisation National Cyber Security Centre
organisation NCSC
attribution Storm-2754
attribution Microsoft Threat Intelligence
attribution SOHO
‎2026/04/09
Forest Blizzard used DNS hijacking and AitM activity to conduct espionage against SOHO routers in a campaign targeting 23 US states, with the infrastructure associated with the campaign disrupted as part of a joint operation.
organisation Forest Blizzard Nabs Rafts
organisation SOHO
threat_actor APT28
organisation Storm-2754
organisation DoJ
organisation Military Unit
organisation the Main Directorate of the General Staff
organisation the Armed Forces of the Russian Federation
organisation Lumen
organisation Black Lotus Labs
organisation Microsoft
organisation DNS
organisation IP
organisation DHCP
organisation Global DNS Hijacking Campaign
organisation UK Security Agency
infrastructure 18,000 unique IP addresses
organisation Feds
victims 200 impacted organizations
infrastructure 5,000 consumer devices
organisation GRU
organisation EU Sanctions Companies
organisation Microsoft Outlook
organisation CVE-2023-50224
organisation VPS
organisation Credential Theft
organisation Operation Masquerade
organisation Microsoft Office
organisation National Cyber Security Centre
organisation CyberScoop
organisation Domain Name System
organisation EDR
organisation VirusTotal
organisation Lumen Technologies
organisation Google Maps
organisation Google
organisation Omdia
organisation SOC
organisation The Hacker News
organisation the U.S. Department of Justice
organisation Federal Bureau of Investigation
organisation AiTM of Transport Layer Security
organisation Microsoft Outlook Web Access
organisation AiTM
organisation MFA
Tactical Metrics
Metrics
infrastructure
‎Microsoft Office
Affected Product
Metrics
infrastructure
18,000
Unique Ip Addresses
Metrics
victims
200
Impacted Organizations
Metrics
infrastructure
5,000
Consumer Devices