Forest Blizzard (Russian GRU Unit 26165) SOHO Router DNS-Hijacking Campaign Enables AitM Credential Theft Against Outlook Web Access — Operation Masquerade
Forest Blizzard (Russian GRU Unit 26165) SOHO Router (TL-2026-1497), also tracked as Operation Masquerade, is a high-severity espionage campaign scored CVSS 6.5, first published 2026-07-18. It is attributed to Forest Blizzard (Russia) with high confidence, affects TP-Link TL-WR841N, references 1 CVE (CVE-2023-50224), maps to 20 MITRE ATT&CK techniques (T1005, T1016, T1036), and is covered by 9 detection rules and 16 indicators of compromise.
Key facts for TL-2026-1497
- Threat ID
- TL-2026-1497
- Also known as
- Operation Masquerade
- Severity
- HIGH
- CVSS
- 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
- Status
- ACTIVE
- Category
- ESPIONAGE
- First published
- 2026-07-18
- Last reviewed
- 2026-07-18
- Attribution
- Forest Blizzard
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- government administration, telecoms, energy, information technology, critical infrastructure, consumer home users, police - law enforcement
- Target regions
- Africa, North America, Europe, 013 - Central America, Southeast Asia, Global
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in Forest Blizzard (Russian GRU Unit 26165) SOHO Router
Malware and tooling: Dual-cluster DNS hijack infrastructure, dnsmasq
Forest Blizzard (APT28/Fancy Bear, Russian GRU 85th GTsSS Military Unit 26165) compromised thousands of small office/home office (SOHO) routers — chiefly end-of-life TP-Link TL-WR841N devices via CVE-2023-50224 and secondarily MikroTik routers — rewriting DHCP/DNS settings so victim traffic is silently redirected through actor-controlled dnsmasq resolvers into adversary-in-the-middle infrastructure that presents spoofed TLS certificates to harvest Microsoft Outlook Web Access credentials, session cookies, and MFA tokens. Microsoft telemetry logged 200+ organizations and 5,000+ consumer devices affected, peaking at 18,000+ hijacked routers across 120+ countries in December 2025; on 2026-04-07 the FBI, DOJ, NSA and a 23-agency international coalition publicly disclosed and remediated the U.S. footprint of the botnet under the court-authorized 'Operation Masquerade.'
How Forest Blizzard (Russian GRU Unit 26165) SOHO Router works
Forest Blizzard — Microsoft's designation for the GRU 85th Main Special Service Center (GTsSS) Military Unit 26165 actor more widely known as APT28, Fancy Bear, Sofacy, and Sednit — has run a large-scale espionage campaign that abandons phishing-link delivery in favor of network-level adversary-in-the-middle (AitM) interception staged from compromised consumer and small-office routers.
The actor, operating a sub-cluster tracked as Storm-2754, obtained unauthorized access to SOHO routers beginning at least 2024 (per FBI/IC3), scaling into large-volume operations from August 2025 onward (per Microsoft telemetry). Initial access to the primary target set — end-of-life TP-Link TL-WR841N routers — was achieved via CVE-2023-50224, an unauthenticated improper-authentication vulnerability in the device's httpd/TDDP service that discloses stored Dropbear SSH credentials from /tmp/dropbear/dropbearpwd over plain HTTP GET requests. Where routers still used vendor-default or weak administrative credentials, GRU operators also brute-forced or reused leaked default logins to gain admin access directly. A secondary MikroTik router cluster was used for more interactive, hands-on-keyboard operations, notably against Ukraine-adjacent infrastructure.
Once inside a router's administrative interface, the actor modified DHCP-issued DNS server settings (DHCP spoofing) so that every LAN client silently resolves DNS through an actor-controlled resolver rather than the ISP's or a public resolver. The hijacked resolvers ran the open-source dnsmasq utility listening on TCP/UDP port 53, allowing the actor to answer queries for specific high-value domains (predominantly outlook.office.com and related Microsoft 365 authentication endpoints) with attacker-controlled IP addresses while passing all other DNS traffic through unmodified — minimizing victim-visible disruption and evading casual detection.
Traffic to the spoofed domains was routed to AitM relay infrastructure that terminated the client's TLS session with an invalid/self-signed certificate masquerading as the legitimate Microsoft service, then proxied credentials, session cookies, and OAuth/MFA tokens through to the real service to keep the session alive while capturing the authentication material server-side. Victims who dismissed browser or mail-client certificate warnings had their plaintext traffic — including email content — exposed to the actor for the duration of the session. Microsoft specifically observed non-Microsoft-hosted government mail servers in at least three African countries targeted through this same DNS-hijack-to-AitM chain, indicating the technique generalizes beyond Microsoft 365 to any TLS service the actor chooses to spoof.
Campaign scale peaked in December 2025 with more than 18,000 uniquely hijacked routers spanning at least 120 countries feeding DNS query telemetry and credential material to GRU-controlled infrastructure, organized as two server clusters: one performing DNS interception at the edge and a second forwarding harvested material and interactive-access traffic to further actor-owned infrastructure. Victim sectors skewed toward government (including foreign-affairs ministries and law enforcement), telecommunications, energy, and IT/cloud-email providers, with reported concentration in North Africa, and additional victims in Central America, Southeast Asia, and Europe; over 23 U.S. states had affected TP-Link devices.
On 2026-04-07, the FBI (led by FBI Boston), DOJ, NSA, and 23 partner agencies (including Canada, Czech Republic, Denmark, Estonia, Finland, Germany, and Italy) publicly attributed the campaign to GRU Military Unit 26165 and executed a court-authorized remediation operation ('Operation Masquerade') that sent commands to compromised routers in the United States to collect evidence, reset hijacked DNS settings, and block the GRU's original access mechanism, without altering the routers' legitimate functionality (reversible by the owner via factory reset). Truesec's 2026-07-16 report indicates the underlying TTP — router compromise leading to DNS-based AitM credential harvesting — remains an active, ongoing GRU capability against unprotected SOHO devices outside the remediated U.S. footprint.
MITRE ATT&CK techniques used in TL-2026-1497
Collection
T1005 Data from Local System; T1114 Email Collection; T1557 Adversary-in-the-Middle
Discovery
T1016 System Network Configuration Discovery
Defense Evasion
Exfiltration
T1041 Exfiltration Over C2 Channel
Command and Control
T1071 Application Layer Protocol
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application
Credential Access
T1110 Brute Force; T1111 Multi-Factor Authentication Interception; T1557 Adversary-in-the-Middle; T1606 Forge Web Credentials
Resource Development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1588 Obtain Capabilities
Reconnaissance
T1590 Gather Victim Network Information; T1595.002 Vulnerability Scanning
defense-impairment
Affected products and versions in Forest Blizzard (Russian GRU Unit 26165) SOHO Router
- TP-Link — TL-WR841N
Vulnerable versions: firmware prior to November 2024 security update
Fixed in: firmware released November 2024 addressing CVE-2023-50224 - TP-Link — TL-WR940N
Vulnerable versions: v6, end-of-support - MikroTik — RouterOS-based SOHO/edge routers
Vulnerable versions: unspecified models used for secondary/interactive access - Generic — Unprotected consumer/SOHO routers with weak or default administrative credentials
Vulnerable versions: any device with unchanged default credentials or exposed remote administration
Remediation for Forest Blizzard (Russian GRU Unit 26165) SOHO Router
Patches
- TP-Link firmware update (November 2024) resolving CVE-2023-50224 improper authentication in httpd/TDDP service
Immediate actions
- Factory-reset and re-provision any SOHO router showing unexpected DNS server entries, especially end-of-life TP-Link TL-WR841N and MikroTik devices
- Replace weak/default router administrative credentials with strong unique passwords
- Disable remote/WAN-facing router administration interfaces
- Update TP-Link router firmware to the November 2024+ release that patches CVE-2023-50224 (or retire unsupported EOL hardware)
- Investigate any browser or mail-client TLS certificate warnings for Outlook/Microsoft 365 as potential AitM indicators rather than dismissing them
- Review DNS logs for unexpected resolver IPs and dnsmasq (port 53) traffic to non-ISP infrastructure
Workarounds
- Disable TDDP and remote HTTP administration on affected TP-Link devices if firmware cannot be updated
- Statically configure trusted DNS resolvers (e.g., via DNS over HTTPS) on endpoints to bypass a hijacked router's DHCP-issued DNS server
Longer-term hardening
- Enforce Zero Trust DNS (ZTDNS) on managed Windows endpoints so DNS resolution is cryptographically bound to approved resolvers
- Move to passwordless / hardware-token (FIDO2) authentication to remove phishable credentials from the AitM attack surface
- Implement continuous access evaluation and Conditional Access requiring compliant/MDM-enrolled devices for Microsoft 365 sign-in
- Prohibit consumer/home-router VPN or split-tunnel configurations for corporate remote access; require managed, centrally administered network egress
- Maintain an asset inventory and lifecycle-replacement policy for edge network devices to eliminate end-of-life routers
CVEs associated with Forest Blizzard (Russian GRU Unit 26165) SOHO Router
CVE-2023-50224
Weaknesses (CWE) in Forest Blizzard (Russian GRU Unit 26165) SOHO Router
CWE-287, CWE-306
Timeline of Forest Blizzard (Russian GRU Unit 26165) SOHO Router
- GRU Military Unit 26165 (Forest Blizzard) actors begin exploiting known router vulnerabilities to steal credentials for thousands of TP-Link devices worldwide, per FBI/IC3 assessment ('since at least 2024').
- Microsoft telemetry shows Forest Blizzard scaling large-volume DNS-hijacking-to-AiTM operations against Outlook Web Access and other TLS services ('since at least August 2025').
- Campaign peaks with more than 18,000 uniquely hijacked routers across at least 120 countries feeding DNS query and credential telemetry to GRU-controlled infrastructure.
- Microsoft quantifies campaign impact at over 200 affected organizations and 5,000+ consumer devices, concentrated in government, IT, telecommunications, and energy sectors, including at least three non-Microsoft-hosted government mail servers in Africa; a 23-agency international coalition (FBI, DOJ, NSA plus partners including Canada, Czech Republic, Denmark, Estonia, Finland, Germany, and Italy) is credited with the joint attribution and disruption.
- FBI executes court-authorized 'Operation Masquerade,' sending remote commands to compromised U.S. routers to collect evidence, reset hijacked DNS settings, and block the GRU's unauthorized access mechanism.
- Microsoft Security publishes technical analysis of the SOHO router DNS hijacking and AiTM campaign against Outlook Web Access.
- FBI, DOJ, NSA, and partner agencies from 15 countries publicly attribute the campaign to GRU Military Unit 26165 and release IC3 PSA I-040726-PSA.
- Truesec reports the DNS-hijack/AiTM TTP remains an active, large-scale Forest Blizzard capability against unprotected SOHO routers outside the remediated U.S. footprint, prompting this threat entry.
Sources cited for Forest Blizzard (Russian GRU Unit 26165) SOHO Router
- Russian Intelligence Targets SOHO Routers
- Russian Espionage Campaign Targets Home Routers
- SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks
- Forest Blizzard leverages router compromises to launch AiTM attacks, target Outlook sessions
- Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking Campaign
- Russia's Forest Blizzard Nabs Rafts of Logins via SOHO Routers
- US operation evicts Russia from hacked SOHO routers used to breach critical infrastructure
- Justice Department Conducts Court-Authorized Disruption of DNS Hijacking Network Controlled by a Russian Military Intelligence Unit
- Russian GRU Exploiting Vulnerable Routers to Steal Sensitive Information (IC3 PSA I-040726-PSA)
- APT28, Forest Blizzard — MITRE ATT&CK Group G0007
- CVE-2023-50224 Detail
- Security Advisory for CVE-2023-50224 – Impact on Legacy TP-Link Router and Access Point Products
- CVE-2023-50224: TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure
- CISA Flags TP-Link Router Flaws CVE-2023-50224 and CVE-2025-9377 as Actively Exploited
Threats related to Forest Blizzard (Russian GRU Unit 26165) SOHO Router
- FSB Center 16 (Static Tundra / Berserk Bear) Exploits Default/Weak SNMP and Unpatched Cisco Smart Install (CVE-2018-0171) to Compromise Networking Devices — AA26-194A
- Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco Smart Install Flaw Against Critical Infrastructure
- Rapid7 Q2 2026 Threat Landscape Report: Vulnerability Disclosures Double, AI-Assisted Exploitation Compresses Patch Timelines
- Cisco Catalyst SD-WAN CVE-2026-20182 — Critical Authentication Bypass Zero-Day Actively Exploited by UAT-8616 (CVSS 10.0, CISA KEV, ED 26-03)
Detection coverage for TL-2026-1497
As of 2026-07-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1497 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.