Cybersecurity — 2026-04-08

FBI Disrupts GRU Network of 18,000 Compromised SOHO Routers Used for DNS Hijacking and Token Theft

Microsoft, the FBI, and IC3 disclosed on April 7 that GRU-linked APT28 (Forest Blizzard) compromised over 18,000 end-of-life Mikrotik and TP-Link SOHO routers to conduct DNS hijacking and harvest Microsoft Office authentication tokens. Microsoft identified 200+ organizations and 5,000 consumer devices affected, including government ministries across multiple continents. The FBI's Operation Masquerade disrupted the US portion of the network. The campaign targeted government agencies, law enforcement, IT providers, and energy organizations, primarily via adversary-in-the-middle attacks after modifying router DNS settings.

Analysis
The DNS hijacking method for token theft is a different operational approach from the Signal phishing campaign reported in prior cycles; APT28 is running parallel collection programs. The FBI's Operation Masquerade disrupted the US portion, but the global infrastructure likely extends well beyond the neutralized nodes. End-of-life routers remain an unpatched attack surface that no advisory will resolve.
3 sources
  1. Russia Hacked Routers to Steal Microsoft Office Tokens - Krebs on Security
  2. SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks - Microsoft
  3. Russian GRU Exploiting Vulnerable Routers to Steal Sensitive Information - FBI IC3

View in full brief →

UNCLASSIFIED // OPEN SOURCE