Forest Blizzard (Russian GRU Unit 26165) SOHO Router DNS-Hijacking Campaign Enables AitM Credential Theft Against Outlook Web Access — Operation Masquerade — Threadlinqs Intelligence
As of 2026-07-18, Forest Blizzard (Russian GRU Unit 26165) SOHO Router DNS-Hijacking Campaign Enables AitM Credential Theft Against Outlook Web Access — Operation Masquerade is a high-severity espionage threat attributed to Forest Blizzard (APT28 (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-1497 · Severity: HIGH · CVSS: 6.5 · Status: ACTIVE · Category: ESPIONAGE
Attribution: Forest Blizzard (APT28 · Russia · ESPIONAGE
Forest Blizzard (APT28/Fancy Bear, Russian GRU 85th GTsSS Military Unit 26165) compromised thousands of small office/home office (SOHO) routers — chiefly end-of-life TP-Link TL-WR841N devices via
Forest Blizzard — Microsoft's designation for the GRU 85th Main Special Service Center (GTsSS) Military Unit 26165 actor more widely known as APT28, Fancy Bear, Sofacy, and Sednit — has run a large-scale espionage campaign that abandons phishing-link delivery in favor of network-level adversary-in-the-middle (AitM) interception staged from compromised consumer and small-office routers.
The actor, operating a sub-cluster tracked as Storm-2754, obtained unauthorized access to SOHO routers beginning at least 2024 (per FBI/IC3), scaling into large-volume operations from August 2025 onward (per Microsoft telemetry). Initial access to the primary target set — end-of-life TP-Link TL-WR841N routers — was achieved via CVE-2023-50224, an unauthenticated improper-authentication vulnerability in the device's httpd/TDDP service that discloses stored Dropbear SSH credentials from /tmp/dropbear/dropbearpwd over plain HTTP GET requests. Where routers still used vendor-default or weak administrative credentials, GRU operators also brute-forced or reused leaked default logins to gain admin access directly. A secondary MikroTik router cluster was used for more interactive, hands-on-keyboard operations, notably against Ukraine-adjacent infrastructure.
Once inside a router's administrative interface, the actor modified DHCP-issued DNS server settings (DHCP spoofing) so that every LAN client silently resolves DNS through an actor-controlled resolver rather than the ISP's or a public resolver. The hijacked resolvers ran the open-source dnsmasq utility listening on TCP/UDP port 53, allowing the actor to answer queries for specific high-value domains (predominantly outlook.office.com and related Microsoft 365 authentication endpoints) with attacker-controlled IP addresses while passing all other DNS traffic through unmodified — minimizing victim-visible disruption and evading casual detection.
Traffic to the spoofed domains was routed to AitM relay infrastructure that terminated the client's TLS session with an invalid/self-signed certificate masquerading as the legitimate Microsoft service, then proxied credentials, session cookies, and OAuth/MFA tokens through to the real service to keep the session alive while capturing the authentication material server-side. Victims who dismissed browser or mail-client certificate warnings had their plaintext traffic — including email content — exposed to the actor for the duration of the session. Microsoft specifically observed non-Microsoft-hosted government mail servers in at least three African countries targeted through this same DNS-hijack-to-AitM chain, indicating the technique generalizes beyond Microsoft 365 to any TLS service the actor chooses to spoof.
Campaign scale peaked in December 2025 with more than 18,000 uniquely hijacked routers spanning at least 120 countries feeding DNS query telemetry and credential material to GRU-controlled infrastructure, organized as two server clusters: one performing DNS interception at the edge and a second forwarding harvested material and interactive-access traffic to further actor-owned infrastructure. Victim sectors skewed toward government (including foreign-affairs ministries and law enforcement), telecommunications, energy, and IT/cloud-email providers, with reported concentration in North Africa, and additional victims in Central America, Southeast Asia, and Europe; over 23 U.S. states had affected TP-Link devices.
On 2026-04-07, the FBI (led by FBI Boston), DOJ, NSA, and 23 partner agencies (including Canada, Czech Republic, Denmark, Estonia, Finland, Germany, and Italy) publicly attributed the campaign to GRU Military Unit 26165 and executed a court-authorized remediation operation ('Operation Masquerade') that sent commands to compromised routers in the United States to collect evidence, reset hijacked DNS settings, and block the GRU's original access mechanism, without altering the routers' legitimate functionality (reversible by the owner via factor
Weaknesses (CWE)
CWE-287, CWE-306
Target sectors: government administration, telecoms, energy, information technology, critical infrastructure, consumer home users, police - law enforcement
Target regions: Africa, North America, Europe, 013 - Central America, Southeast Asia, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
ESPIONAGE, HIGH, threat intelligence, cybersecurity, CVE-2023-50224, T1595.002, T1590, T1583, T1584, T1588, T1190, T1133, T1078, T1601, T1036