Russian Hackers Use Router DNS Hijacking to Steal Microsoft Office Tokens

Russian military intelligence has been leveraging known vulnerabilities in aging internet hardware to execute a massive surveillance operation, allowing them to steal Microsoft Office authentication tokens from thousands of users. The campaign, which targets Minor Office/Home Office (SOHO) routers, enables state-backed hackers to bypass multi-factor authentication and gain direct access to sensitive accounts without the require for traditional phishing or malware installation.

The operation is attributed to a threat actor known as Forest Blizzard, too identified as APT28, Fancy Bear, and Sednit. This unit is linked to the Russian military intelligence agency, the Main Intelligence Directorate of the General Staff (GRU), specifically Military Unit 26165 according to the U.S. Department of Justice. By compromising the very gateways users use to access the internet, the actors have created a stealthy “dragnet” to siphon data from government agencies and critical infrastructure sectors.

Microsoft recently identified more than 200 organizations and 5,000 consumer devices caught in this network in a security blog post dated April 7, 2026. The attack is particularly dangerous due to the fact that it targets the Domain Name System (DNS) settings of routers, effectively redirecting user traffic to malicious servers controlled by the GRU.

The Mechanics of DNS Hijacking and Token Theft

At the core of this operation is a technique called DNS hijacking. The Domain Name System acts as the internet’s phonebook, translating human-readable web addresses into the IP addresses that computers use to communicate. By exploiting vulnerabilities in older TP-Link and Mikrotik routers, Forest Blizzard modified these settings to point toward their own malicious DNS resolvers.

Once a router is compromised, the attackers can implement an automated filtering process to determine which DNS requests are of interest. For high-value targets, the GRU’s resolvers provide fraudulent DNS records that mimic legitimate services, such as Microsoft Outlook Web Access. This facilitates “Adversary-in-the-Middle” (AiTM) attacks, where the attackers intercept the encrypted traffic between the victim and the real service.

DNS hijacking through router compromise. Image: Microsoft.

The ultimate goal of this redirection is the theft of OAuth authentication tokens. These tokens are generated after a user has already successfully logged in and completed multi-factor authentication (MFA). Because the hackers capture the token itself, they can bypass the login process entirely and gain immediate access to the victim’s account, rendering MFA ineffective in these specific scenarios.

Scale of the Forest Blizzard Campaign

The reach of this operation has been extensive. Researchers at Black Lotus Labs, a security division of the internet backbone provider Lumen, discovered that at the peak of its activity in December 2025, the surveillance network ensnared more than 18,000 internet routers. The majority of these devices were unsupported, end-of-life, or severely outdated in terms of security patches.

How targeted DNS requests were redirected at the router
How targeted DNS requests were redirected at the router. Image: Black Lotus Labs.

The targeting was not random. While the initial compromise of routers was indiscriminate, the subsequent interception focused on government agencies, including law enforcement and ministries of foreign affairs, as well as third-party email providers. This shift in strategy occurred after a similar report from the U.K.’s National Cyber Security Centre (NCSC) in August 2025, which prompted the group to move away from malware-based control toward a more systemic, DNS-based approach.

U.S. Government Response and Hardware Restrictions

The persistence of these vulnerabilities has led to significant policy shifts in the United States. On Tuesday, April 7, 2026, the Department of Justice and the FBI announced a court-authorized technical operation to neutralize the U.S. Portion of the compromised SOHO router network via an official press release.

U.S. Government Response and Hardware Restrictions

Beyond immediate disruption, the U.S. Federal Communications Commission (FCC) has taken a broader stance on hardware security. On March 23, the FCC announced it would no longer certify consumer-grade internet routers produced outside of the United States, citing them as an untenable national security threat. The commission warned that poorly secured routers could be leveraged to disrupt critical infrastructure and harm U.S. Persons.

Key Takeaways for Users and Organizations

  • Update Hardware: The attacks primarily targeted end-of-life or unsupported routers. Ensuring firmware is up to date is critical.
  • MFA is Not a Silver Bullet: While multi-factor authentication is essential, AiTM attacks can steal tokens after MFA is completed.
  • Audit DNS Settings: Organizations should monitor for unauthorized changes to DNS resolver settings on their edge devices.
  • SOHO Vulnerability: Small office and home office routers are frequently targeted because they often lack the rigorous security monitoring of enterprise-grade hardware.

The ongoing battle against Forest Blizzard highlights a shift in cyber-espionage: the move away from “sexy” or sophisticated malware in favor of “old-school” methods that exploit the fundamental architecture of the internet. By targeting the router—the very door to the network—state actors can maintain a persistent, invisible presence on thousands of devices worldwide.

The U.S. Government and Microsoft continue to monitor the situation as the GRU evolves its tactics. Further updates on the neutralization of these networks are expected as the Department of Justice continues its court-authorized operations.

Do you use a SOHO router for your home or small business? Share your thoughts on the FCC’s new certification policies in the comments below.

Leave a Comment