Skip to content
Authorities disrupt router DNS hijacks used to steal Microsoft 365 logins

Authorities disrupt router DNS hijacks used to steal Microsoft 365 logins

Ground.News April 7, 2026

The UK and Microsoft warn that 'Fancy Bear' hackers are targeting outdated consumer routers, many of which are 'end-of-life' TP-Link devices that no longer receive software patches.

Fancy Bear, also known as APT28, has taken over thousands of residential routers to steal passwords and authentication tokens in a wide-ranging espionage operation.

An international operation from law enforcement authorities in partnership with private companies has disrupted FrostArmada, an APT28 campaign hijacking local traffic from MikroTik and TP-Link routers to steal Microsoft account credentials.

The Russia-linked threat actor known as APT28 (aka Forest Blizzard) has been linked to a new campaign that has compromised insecure MikroTik and TP-Link routers and modified their settings to turn them into malicious infrastructure under their control as part of a cyber espionage campaign since at least May 2025. The large-scale exploitation campaign has been codenamed FrostArmada by Lumen’s Black Lotus Labs, with Microsoft describing it as an e…

The British cybersecurity center NCSC reports cyber attacks on Internet routers. The gang from Russia is also suspicious of several attacks in Germany.

A new alert from the UK ensures that APT28, a group linked to Russian military intelligence, has been exploiting vulnerable routers to hijack DNS traffic, intercept connections and steal mail credentials and web services. The campaign combines public faults, malicious VPS servers and attackers in the middle with an opportunistic approach that is then fine-tuned over higher-value targets. *** The NCSC attributes the activity to APT28, almost cert…

To view factuality data please Upgrade to Premium

To view ownership data please Upgrade to Vantage

Extracted Entities

Campaigns (1)

Companies (3)

Countries (1)

Platforms (1)