GRU Operators Drained Microsoft 365 Tokens by Rewriting DNS on 18,000 SOHO Routers

Forest Blizzard shifted from targeted router malware to mass DNS hijacking after a UK advisory in August, intercepting OAuth tokens on Outlook on the web.

ThreatVectr Newsdesk· 3 min read
GRU Operators Drained Microsoft 365 Tokens by Rewriting DNS on 18,000 SOHO Routers
Share

Russian military intelligence operators tracked as Forest Blizzard (also known as APT28 and Fancy Bear) compromised more than 18,000 older Mikrotik and TP-Link routers across small-office networks to redirect DNS traffic and silently lift Microsoft 365 OAuth tokens, according to research published this week by Black Lotus Labs at Lumen and a parallel disclosure by Microsoft. The campaign peaked in December 2025 and required no malware on the routers themselves.

The group is attributed to Unit 26165 within Russia's Main Intelligence Directorate of the General Staff (GRU), the same operators tied to the 2016 intrusions at the Democratic National Committee. According to Black Lotus Labs, the targeting set leaned toward ministries of foreign affairs, law enforcement bodies, and third-party email providers, with roughly 200 organisations and 5,000 consumer devices observed in the dragnet.

The technique is unglamorous. Operators exploited known, unpatched flaws in end-of-life consumer routers to alter the device's DNS settings, pointing queries at virtual private servers under their control. From there, malicious DNS responses propagated to every client on the local network, enabling adversary-in-the-middle interception of TLS sessions to Outlook on the web domains.

"These guys didn't use malware. They did this in an old-school, graybeard way that isn't really sexy but it gets the job done," said Ryan English, a security engineer at Black Lotus Labs.

Because OAuth tokens are issued only after a user has cleared multi-factor authentication, possession of the token lets the attacker bypass MFA entirely on subsequent requests. No phishing of one-time codes was required.

The operational shift is itself notable. Danny Adamitis, an engineer at Black Lotus Labs, said the group had previously used router-resident malware against a narrower target list, but pivoted to mass DNS rewrites the day after the United Kingdom's National Cyber Security Centre (NCSC) published an advisory in August 2025. "After the report was released they implemented the capability in a more systemic fashion and used it to target everything that was vulnerable," Adamitis said.

The disclosures arrive against a shifting regulatory backdrop. On March 23, the Federal Communications Commission (FCC) announced it would cease certifying consumer-grade routers manufactured outside the United States, citing national security risk. The order preserves devices already in service and permits conditional approval applications routed through the Department of War or the Department of Homeland Security (DHS). Industry analysts have noted that few qualifying domestic products currently exist on the consumer shelf.

NCSC has asked network defenders to audit edge devices for unauthorised DNS configuration changes and to retire unsupported hardware. Microsoft's detection guidance for the AiTM activity is live now. The FCC's certification policy takes effect under its existing equipment authorisation rules; the agency has not yet opened a separate comment window on the foreign-manufacture restriction.

The routers are the soft underbelly. They always were.

© 2026 Threat Vectr