Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionageembedded-device-vulnerabilitycommand-and-control-methodgovernment-diplomatic-threat

Forest Blizzard Hijacks SOHO Router DNS to Enable Adversary-in-the-Middle Attacks

Updated 2mo agoFirst seen Apr 7, 202627 sources

Microsoft said the Russian military-linked threat actor Forest Blizzard (APT28/Strontium) has compromised vulnerable home and small-office routers since at least August 2025, changing DNS settings to route traffic through attacker-controlled resolvers. The campaign affected more than 200 organizations and 5,000 consumer devices across government, IT, telecommunications, and energy, turning edge devices into covert infrastructure and giving the actor passive visibility into victims’ DNS traffic.

For selected high-value targets, the operation escalated into adversary-in-the-middle attacks in which spoofed DNS responses redirected users to systems presenting invalid TLS certificates for legitimate services, including Microsoft Outlook on the web and government servers. Microsoft said confirmed AiTM activity included non-Microsoft government targets in at least three African countries, while stressing that no Microsoft-owned assets or services were compromised; the company urged defenders to patch and harden routers, replace default credentials, audit DNS settings, and train users not to bypass certificate warnings.

Share:
Forest Blizzard Hijacks SOHO Router DNS to Enable Adversary-in-the-Middle Attacks
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

11 events from the most recent confirmed update back to the earliest known activity.

11 EVENTS
Apr 15, 20262mo ago

FBI, NSA, and 15-country partners issue router security guidance

Following the disruption of the GRU-linked router botnet, the FBI, NSA, and partners from 15 countries issued a public service announcement urging users to replace unsupported routers, update firmware, verify DNS settings, disable internet-exposed remote management, and change default credentials. The guidance was aimed at reducing continued risk from compromised SOHO routers used in the APT28/Forest Blizzard espionage campaign.

FBI urges router owners to update firmware after Russian GRU hack | Fox Business
Apr 8, 20263mo ago

Germany's BfV warns APT28 compromised routers in Germany

On April 8, 2026, Germany's Federal Office for the Protection of the Constitution, together with BND and the FBI, warned that APT28 had compromised vulnerable TP-Link routers for espionage. The agency said several thousand routers were targeted worldwide, including about 30 vulnerable devices in Germany, and confirmed some compromises that led operators to replace affected routers.

teiss - News - Germany intelligence agency warns of Russian APT28 cyber spying

UK NCSC discloses two APT28 router-based credential theft campaigns

The UK National Cyber Security Centre warned of two Russian-linked APT28/Forest Blizzard campaigns abusing compromised SOHO routers for DNS hijacking and adversary-in-the-middle credential theft. It said one cluster altered DHCP DNS settings while another used compromised MikroTik and TP-Link routers to forward DNS traffic through actor-controlled infrastructure, including activity focused on MikroTik routers in Ukraine.

NCSC issues alert over Russian hacker campaign targeting SOHO routers | IT Pro
Apr 7, 20263mo ago

FBI resets malicious DNS settings on compromised TP-Link routers

As part of Operation Masquerade, the FBI carried out a court-authorized technical operation against the U.S. portion of the APT28/Forest Blizzard router network, resetting malicious DNS settings on compromised TP-Link SOHO routers to legitimate ISP resolvers and blocking the attackers’ original access method. The DOJ said affected routers were located in more than 23 U.S. states and that the action was designed not to disrupt normal router functionality or collect users’ content.

Office of Public Affairs | Justice Department Conducts Court-Authorized Disruption of DNS Hijacking Network Controlled by a Russian Military Intelligence Unit | United States Department of Justice

DOJ, FBI, and partners disrupt APT28 malicious infrastructure

A joint operation involving the U.S. Department of Justice, the FBI, and international partners disrupted the malicious infrastructure used in the APT28/Forest Blizzard DNS hijacking campaign. The action targeted infrastructure supporting the compromise of SOHO routers and downstream espionage activity.

Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking Campaign

Microsoft publicly discloses the campaign and attribution

On April 7, 2026, Microsoft Threat Intelligence publicly reported the campaign, attributing it to Forest Blizzard, a Russian military-linked threat actor also known as APT28 or Strontium. Microsoft said it was the first observed instance of the group using DNS hijacking at scale to support TLS AiTM operations after edge-device exploitation and noted no Microsoft-owned assets or services were compromised.

Forest Blizzard conducts selective AiTM attacks via spoofed DNS responses

In selected cases, the actor escalated from passive DNS collection to adversary-in-the-middle attacks by spoofing DNS responses for Outlook on the web and certain government servers, including activity affecting targets in at least three African nations. Victims were presented invalid TLS certificates, allowing interception of plaintext traffic if certificate warnings were ignored.

DNS hijacking campaign affects thousands of devices and hundreds of organizations

Over the course of the campaign, the router compromises led to DNS hijacking impacting more than 200 organizations and 5,000 consumer devices across government, IT, telecommunications, and energy sectors. Microsoft said this represented large-scale abuse of edge devices for downstream victim visibility.

Dec 1, 20257mo ago

FrostArmada peaks with 18,000 infected routers across 120 countries

At its peak in December 2025, the APT28-attributed FrostArmada campaign had compromised about 18,000 MikroTik and TP-Link SOHO routers in 120 countries. The operation primarily targeted government agencies, law enforcement organizations, and IT providers by altering DNS settings to enable adversary-in-the-middle credential and token theft.

FrostArmada campaign disrupted: APT28 router hijacking operation halted | brief | SC Media
Aug 1, 202511mo ago

Forest Blizzard begins exploiting vulnerable SOHO routers

Since at least August 2025, Microsoft assessed that Forest Blizzard began compromising vulnerable home and small-office routers and changing their DNS settings to actor-controlled resolvers. The activity turned the devices into covert malicious infrastructure for intelligence collection.

Jan 1, 20242y ago

APT28 begins router campaign exploiting TP-Link flaw CVE-2023-50224

The IC3 advisory says Russian GRU actors behind APT28/Forest Blizzard had been exploiting vulnerable SOHO routers worldwide since at least 2024, including TP-Link devices vulnerable to CVE-2023-50224. The compromises enabled changes to DHCP and DNS settings that supported later DNS hijacking and adversary-in-the-middle operations.

Internet Crime Complaint Center (IC3) | Russian GRU Exploiting Vulnerable Routers to Steal Sensitive Information
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

45 LINKEDOpen in app
Affected products
6 linked
Microsoft OfficeOutlook Web AccessMicrosoft Defender For EndpointWindowsMicrosoft AccountMicrosoft Authenticator
Organizations
30 linked
TP-LinkMicrosoft CorporationRubrikFox BusinessMikrotikLumen TechnologiesGoogleLinkedinXAppleCisco SystemsBleepingComputerMalwarebytesTom's HardwareTechCrunchL3Harris TechnologiesAnthropicFortinetCrowdStrikeReutersZDNETViaSatThe Cyber ExpressCyberScoopHasbroSunrunThe Hacker NewsIT ProNethesisUK Defence Journal
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.