Forest Blizzard (Russian GRU Unit 26165) SOHO Router DNS-Hijacking Campaign Enables AitM Credential Theft Against Outlook Web Access — Operation Masquerade

Forest Blizzard (Russian GRU Unit 26165) SOHO Router (TL-2026-1497), also tracked as Operation Masquerade, is a high-severity espionage campaign scored CVSS 6.5, first published 2026-07-18. It is attributed to Forest Blizzard (Russia) with high confidence, affects TP-Link TL-WR841N, references 1 CVE (CVE-2023-50224), maps to 20 MITRE ATT&CK techniques (T1005, T1016, T1036), and is covered by 9 detection rules and 16 indicators of compromise.

Key facts for TL-2026-1497

Threat ID
TL-2026-1497
Also known as
Operation Masquerade
Severity
HIGH
CVSS
6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Status
ACTIVE
Category
ESPIONAGE
First published
2026-07-18
Last reviewed
2026-07-18
Attribution
Forest Blizzard
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
government administration, telecoms, energy, information technology, critical infrastructure, consumer home users, police - law enforcement
Target regions
Africa, North America, Europe, 013 - Central America, Southeast Asia, Global
Detection rules
9
Indicators of compromise
16

Malware and tooling in Forest Blizzard (Russian GRU Unit 26165) SOHO Router

Malware and tooling: Dual-cluster DNS hijack infrastructure, dnsmasq

Forest Blizzard (APT28/Fancy Bear, Russian GRU 85th GTsSS Military Unit 26165) compromised thousands of small office/home office (SOHO) routers — chiefly end-of-life TP-Link TL-WR841N devices via CVE-2023-50224 and secondarily MikroTik routers — rewriting DHCP/DNS settings so victim traffic is silently redirected through actor-controlled dnsmasq resolvers into adversary-in-the-middle infrastructure that presents spoofed TLS certificates to harvest Microsoft Outlook Web Access credentials, session cookies, and MFA tokens. Microsoft telemetry logged 200+ organizations and 5,000+ consumer devices affected, peaking at 18,000+ hijacked routers across 120+ countries in December 2025; on 2026-04-07 the FBI, DOJ, NSA and a 23-agency international coalition publicly disclosed and remediated the U.S. footprint of the botnet under the court-authorized 'Operation Masquerade.'

How Forest Blizzard (Russian GRU Unit 26165) SOHO Router works

Forest Blizzard — Microsoft's designation for the GRU 85th Main Special Service Center (GTsSS) Military Unit 26165 actor more widely known as APT28, Fancy Bear, Sofacy, and Sednit — has run a large-scale espionage campaign that abandons phishing-link delivery in favor of network-level adversary-in-the-middle (AitM) interception staged from compromised consumer and small-office routers.

The actor, operating a sub-cluster tracked as Storm-2754, obtained unauthorized access to SOHO routers beginning at least 2024 (per FBI/IC3), scaling into large-volume operations from August 2025 onward (per Microsoft telemetry). Initial access to the primary target set — end-of-life TP-Link TL-WR841N routers — was achieved via CVE-2023-50224, an unauthenticated improper-authentication vulnerability in the device's httpd/TDDP service that discloses stored Dropbear SSH credentials from /tmp/dropbear/dropbearpwd over plain HTTP GET requests. Where routers still used vendor-default or weak administrative credentials, GRU operators also brute-forced or reused leaked default logins to gain admin access directly. A secondary MikroTik router cluster was used for more interactive, hands-on-keyboard operations, notably against Ukraine-adjacent infrastructure.

Once inside a router's administrative interface, the actor modified DHCP-issued DNS server settings (DHCP spoofing) so that every LAN client silently resolves DNS through an actor-controlled resolver rather than the ISP's or a public resolver. The hijacked resolvers ran the open-source dnsmasq utility listening on TCP/UDP port 53, allowing the actor to answer queries for specific high-value domains (predominantly outlook.office.com and related Microsoft 365 authentication endpoints) with attacker-controlled IP addresses while passing all other DNS traffic through unmodified — minimizing victim-visible disruption and evading casual detection.

Traffic to the spoofed domains was routed to AitM relay infrastructure that terminated the client's TLS session with an invalid/self-signed certificate masquerading as the legitimate Microsoft service, then proxied credentials, session cookies, and OAuth/MFA tokens through to the real service to keep the session alive while capturing the authentication material server-side. Victims who dismissed browser or mail-client certificate warnings had their plaintext traffic — including email content — exposed to the actor for the duration of the session. Microsoft specifically observed non-Microsoft-hosted government mail servers in at least three African countries targeted through this same DNS-hijack-to-AitM chain, indicating the technique generalizes beyond Microsoft 365 to any TLS service the actor chooses to spoof.

Campaign scale peaked in December 2025 with more than 18,000 uniquely hijacked routers spanning at least 120 countries feeding DNS query telemetry and credential material to GRU-controlled infrastructure, organized as two server clusters: one performing DNS interception at the edge and a second forwarding harvested material and interactive-access traffic to further actor-owned infrastructure. Victim sectors skewed toward government (including foreign-affairs ministries and law enforcement), telecommunications, energy, and IT/cloud-email providers, with reported concentration in North Africa, and additional victims in Central America, Southeast Asia, and Europe; over 23 U.S. states had affected TP-Link devices.

On 2026-04-07, the FBI (led by FBI Boston), DOJ, NSA, and 23 partner agencies (including Canada, Czech Republic, Denmark, Estonia, Finland, Germany, and Italy) publicly attributed the campaign to GRU Military Unit 26165 and executed a court-authorized remediation operation ('Operation Masquerade') that sent commands to compromised routers in the United States to collect evidence, reset hijacked DNS settings, and block the GRU's original access mechanism, without altering the routers' legitimate functionality (reversible by the owner via factory reset). Truesec's 2026-07-16 report indicates the underlying TTP — router compromise leading to DNS-based AitM credential harvesting — remains an active, ongoing GRU capability against unprotected SOHO devices outside the remediated U.S. footprint.

MITRE ATT&CK techniques used in TL-2026-1497

Collection

T1005 Data from Local System; T1114 Email Collection; T1557 Adversary-in-the-Middle

Discovery

T1016 System Network Configuration Discovery

Defense Evasion

T1036 Masquerading

Exfiltration

T1041 Exfiltration Over C2 Channel

Command and Control

T1071 Application Layer Protocol

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application

Credential Access

T1110 Brute Force; T1111 Multi-Factor Authentication Interception; T1557 Adversary-in-the-Middle; T1606 Forge Web Credentials

Resource Development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1588 Obtain Capabilities

Reconnaissance

T1590 Gather Victim Network Information; T1595.002 Vulnerability Scanning

defense-impairment

T1599 Network Boundary Bridging; T1601 Modify System Image

Affected products and versions in Forest Blizzard (Russian GRU Unit 26165) SOHO Router

  • TP-Link — TL-WR841N
    Vulnerable versions: firmware prior to November 2024 security update
    Fixed in: firmware released November 2024 addressing CVE-2023-50224
  • TP-Link — TL-WR940N
    Vulnerable versions: v6, end-of-support
  • MikroTik — RouterOS-based SOHO/edge routers
    Vulnerable versions: unspecified models used for secondary/interactive access
  • Generic — Unprotected consumer/SOHO routers with weak or default administrative credentials
    Vulnerable versions: any device with unchanged default credentials or exposed remote administration

Remediation for Forest Blizzard (Russian GRU Unit 26165) SOHO Router

Patches

  • TP-Link firmware update (November 2024) resolving CVE-2023-50224 improper authentication in httpd/TDDP service

Immediate actions

  • Factory-reset and re-provision any SOHO router showing unexpected DNS server entries, especially end-of-life TP-Link TL-WR841N and MikroTik devices
  • Replace weak/default router administrative credentials with strong unique passwords
  • Disable remote/WAN-facing router administration interfaces
  • Update TP-Link router firmware to the November 2024+ release that patches CVE-2023-50224 (or retire unsupported EOL hardware)
  • Investigate any browser or mail-client TLS certificate warnings for Outlook/Microsoft 365 as potential AitM indicators rather than dismissing them
  • Review DNS logs for unexpected resolver IPs and dnsmasq (port 53) traffic to non-ISP infrastructure

Workarounds

  • Disable TDDP and remote HTTP administration on affected TP-Link devices if firmware cannot be updated
  • Statically configure trusted DNS resolvers (e.g., via DNS over HTTPS) on endpoints to bypass a hijacked router's DHCP-issued DNS server

Longer-term hardening

  • Enforce Zero Trust DNS (ZTDNS) on managed Windows endpoints so DNS resolution is cryptographically bound to approved resolvers
  • Move to passwordless / hardware-token (FIDO2) authentication to remove phishable credentials from the AitM attack surface
  • Implement continuous access evaluation and Conditional Access requiring compliant/MDM-enrolled devices for Microsoft 365 sign-in
  • Prohibit consumer/home-router VPN or split-tunnel configurations for corporate remote access; require managed, centrally administered network egress
  • Maintain an asset inventory and lifecycle-replacement policy for edge network devices to eliminate end-of-life routers

CVEs associated with Forest Blizzard (Russian GRU Unit 26165) SOHO Router

CVE-2023-50224

Weaknesses (CWE) in Forest Blizzard (Russian GRU Unit 26165) SOHO Router

CWE-287, CWE-306

Timeline of Forest Blizzard (Russian GRU Unit 26165) SOHO Router

  • GRU Military Unit 26165 (Forest Blizzard) actors begin exploiting known router vulnerabilities to steal credentials for thousands of TP-Link devices worldwide, per FBI/IC3 assessment ('since at least 2024').
  • Microsoft telemetry shows Forest Blizzard scaling large-volume DNS-hijacking-to-AiTM operations against Outlook Web Access and other TLS services ('since at least August 2025').
  • Campaign peaks with more than 18,000 uniquely hijacked routers across at least 120 countries feeding DNS query and credential telemetry to GRU-controlled infrastructure.
  • Microsoft quantifies campaign impact at over 200 affected organizations and 5,000+ consumer devices, concentrated in government, IT, telecommunications, and energy sectors, including at least three non-Microsoft-hosted government mail servers in Africa; a 23-agency international coalition (FBI, DOJ, NSA plus partners including Canada, Czech Republic, Denmark, Estonia, Finland, Germany, and Italy) is credited with the joint attribution and disruption.
  • FBI executes court-authorized 'Operation Masquerade,' sending remote commands to compromised U.S. routers to collect evidence, reset hijacked DNS settings, and block the GRU's unauthorized access mechanism.
  • Microsoft Security publishes technical analysis of the SOHO router DNS hijacking and AiTM campaign against Outlook Web Access.
  • FBI, DOJ, NSA, and partner agencies from 15 countries publicly attribute the campaign to GRU Military Unit 26165 and release IC3 PSA I-040726-PSA.
  • Truesec reports the DNS-hijack/AiTM TTP remains an active, large-scale Forest Blizzard capability against unprotected SOHO routers outside the remediated U.S. footprint, prompting this threat entry.

Sources cited for Forest Blizzard (Russian GRU Unit 26165) SOHO Router

Threats related to Forest Blizzard (Russian GRU Unit 26165) SOHO Router

Detection coverage for TL-2026-1497

As of 2026-07-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1497 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats