Russian Intelligence Unit Forest Blizzard Uses DNS Hijacking to Mass
Hackers linked to Russia's GRU compromised thousands of end-of-life routers to intercept OAuth tokens, bypassing multi-factor authentication without using
Security reporter
Reports on cybersecurity incidents, threat actors, and digital policy with a focus on technical claims, vendor disclosures, and security-response timelines.
Editorial responsibility: Lead reviewer for threat attribution, incident framing, and security vendor claims
Primary source: Krebs on Security. Full source links and update notes are below.
Fast summary
Start here
- Forest Blizzard (APT28) exploited known flaws in older Mikrotik and TP-Link routers to redirect DNS traffic to attacker-controlled servers.
- The campaign ensnared over 18,000 networks at its peak, primarily targeting government agencies, ministries of foreign affairs, and law enforcement.
- By intercepting OAuth tokens, the attackers gained direct access to victim accounts, effectively bypassing multi-factor authentication protocols.

What happened
Security researchers say the Russian intelligence-linked group known as Forest Blizzard hijacked more than 18,000 routers in order to steal Microsoft Office authentication tokens at scale. The campaign reportedly relied on DNS hijacking through older, vulnerable edge devices rather than traditional endpoint malware. By compromising routers and redirecting traffic through attacker-controlled infrastructure, the operators were able to intercept OAuth tokens after victims had already authenticated, giving them account access without having to defeat credentials directly at the login page.
That makes the campaign particularly serious because it attacks trust in the network path itself. Instead of infecting the victim's laptop, the attackers manipulate the device sitting between the user and the internet.
What's new in this update
The most important development is the scale and the method together. Researchers from Microsoft and Lumen's Black Lotus Labs say this is not just another APT28 operation. It is a large, infrastructure-centric espionage campaign using end-of-life or poorly maintained routers as the entry point for adversary-in-the-middle interception. That tactic lets the attackers bypass some of the visibility and detection logic that organizations have spent years building around malware, EDR tooling, and endpoint compromise.
It also exposes a harsh operational truth: organizations may invest heavily in identity protection and MFA while still leaving older network devices weak enough to undermine the whole chain.
Key details
The targeted hardware reportedly included unsupported or unpatched Mikrotik and TP-Link routers. Once attackers gained control, they altered DNS settings so user traffic resolved through hostile infrastructure. When victims authenticated into Microsoft services, the attackers intercepted the resulting OAuth or session-related artifacts and used them to access accounts directly.
Several factors make the operation notable:
- It relies on router compromise rather than endpoint malware.
- It can capture tokens after successful login, effectively neutralizing MFA's intended protection.
- It reportedly affected government, diplomatic, and law-enforcement networks at scale.
- It demonstrates continued strategic value in aging edge infrastructure.
This is why the campaign is so troubling for defenders. It does not need to beat the newest laptop protections if it can quietly take over the forgotten networking gear outside the office wall.
Background and context
Forest Blizzard, also known as APT28 or Fancy Bear, has long been associated with Russia's GRU and with politically significant cyber operations. The group is known for adapting old techniques to new environments when those techniques still work. DNS manipulation is not glamorous, but it is foundational. If an attacker can alter name resolution or reroute traffic through a malicious vantage point, many modern controls become less effective.
This is especially dangerous in small-office, branch-office, and remote environments where routers may stay in service for years after vendor support degrades. In such environments, the edge device often becomes the weakest link in an otherwise well-defended identity stack.
What to watch next
The immediate question is how quickly organizations replace or harden vulnerable network devices, especially in government and critical-administration environments. Token theft campaigns are difficult enough when the compromise sits on the endpoint; when the compromise sits in the routing layer, detection and remediation become even more complex.
Researchers will also watch whether Forest Blizzard shifts tactics now that the method is public. But even if this specific infrastructure is disrupted, the broader lesson remains: attackers will keep targeting neglected routers as long as they provide a quiet route around stronger endpoint and identity defenses.
Why this matters
This matters because Forest Blizzard, APT28, Fancy Bear, Microsoft Office, DNS hijacking, OAuth token theft, and GRU-linked cyber operations all converge on one uncomfortable conclusion: modern security controls can be bypassed if legacy network infrastructure is left exposed. The campaign shows that state actors do not always need zero-days or novel malware to break in. Sometimes they only need thousands of forgotten routers and a protocol old enough that defenders stopped paying attention to it.
Reader context
This story belongs to Northstar Herald's Cybersecurity and National Security coverage, with related entities including Forest Blizzard, APT28, Fancy Bear, Microsoft. The report is based on Krebs on Security source material.
Related coverage
Why it matters
This campaign demonstrates a massive-scale exploitation of unpatched infrastructure that allows state actors to bypass modern security measures without deploying detectable malware.
Read next
Follow this story through the topic hub, more security coverage, and the latest updates.
Weekly briefing
Get the week's key developments in one concise email.
Get a fast catch-up on the biggest stories, the context behind them, and the links worth your time.
Cadence
Weekly, for a quick catch-up
Coverage
AI, business, world, security, sports
Format
Clear takeaways and useful context
Request the briefing
Leave your email to open a prepared request and get on the list for the weekly briefing.
About the byline
Security reporter
Marcus Kane covers cybersecurity, national-security technology, and digital risk, tracking how breaches, state-backed operations, and platform vulnerabilities affect institutions and users.
Sources and methodology