🌐 Nation-State Threats

GRU's Simple Router Trick Nabbed Microsoft Tokens from 18,000 Networks

Over 18,000 routers — mostly dusty old Mikrotik and TP-Link models — got flipped by Russian military hackers last year. They didn't drop malware; just tweaked DNS to swipe Microsoft auth tokens mid-session.

Network diagram showing Russian hackers rerouting DNS on compromised routers to intercept Microsoft tokens

⚡ Key Takeaways

  • GRU's Forest Blizzard hijacked 18K routers via DNS flaws to steal MS Office tokens, no malware needed. 𝕏
  • Targets: 200 orgs + 5K devices, focusing on gov agencies and SOHO gear. 𝕏
  • Old-school tactic scales fast; patch EOL routers or risk AiTM account takeovers. 𝕏
Published by

Threat Digest

Threat intelligence. Zero noise.

Worth sharing?

Get the best Cybersecurity stories of the week in your inbox — no noise, no spam.

Originally reported by Krebs on Security

Stay in the loop

The week's most important stories from Threat Digest, delivered once a week.