GRU's Simple Router Trick Nabbed Microsoft Tokens from 18,000 Networks
Over 18,000 routers — mostly dusty old Mikrotik and TP-Link models — got flipped by Russian military hackers last year. They didn't drop malware; just tweaked DNS to swipe Microsoft auth tokens mid-session.
Threat DigestApr 07, 20263 min read
⚡ Key Takeaways
GRU's Forest Blizzard hijacked 18K routers via DNS flaws to steal MS Office tokens, no malware needed.𝕏
Targets: 200 orgs + 5K devices, focusing on gov agencies and SOHO gear.𝕏