Russia Hijacked Home Routers to Silently Drain Microsoft 365 Sessions

Russia Hijacked Home Routers to Silently Drain Microsoft 365 Sessions

Forest Blizzard's router exploitation campaign bypassed passwords and MFA entirely — and most victims never knew it happened.

Written by OutOfToken AI

May 24, 2026 · 4 min read · Synthesized from reporting by Krebs on Security · How this works

AI Likely Accurate · 8/10

Russia's military intelligence apparatus has been quietly dismantling one of the most fundamental assumptions in enterprise security: that stolen credentials are needed to breach an account. A campaign attributed to the threat group Forest Blizzard — linked to the GRU, Russia's military intelligence directorate — exploited known vulnerabilities in aging consumer and small-business routers to harvest Microsoft Office authentication tokens at scale, compromising more than 200 organizations and approximately 5,000 devices. No malware. No phishing. No cracked passwords. Just intercepted session tokens and complete, invisible access.

The Anatomy of a Token Harvest

Authentication tokens are the digital keys issued after a user successfully logs in — and critically, after they complete multi-factor authentication. Once a valid token is captured, an attacker can replay it to impersonate the user entirely, sidestepping both passwords and MFA codes. Forest Blizzard's operation targeted routers running outdated firmware with publicly documented vulnerabilities, many of which had gone unpatched for months or years on home networks and small-office deployments. By compromising the routers themselves — the devices that route all outbound traffic — the attackers positioned themselves to intercept OAuth tokens and session credentials flowing through Microsoft 365 and Office services without ever touching an endpoint.

DNS Hijacking as a Post-Compromise Weapon

Microsoft's investigation revealed that Forest Blizzard layered DNS hijacking onto the router compromise to amplify its reach during post-exploitation phases. By manipulating DNS resolution at the router level, attackers could silently redirect authentication traffic — steering credential exchanges through infrastructure they controlled before legitimate Microsoft servers ever saw the request. This technique is particularly insidious because it operates below the visibility horizon of most endpoint detection tools and corporate SIEM platforms. Victims' machines behaved normally; logs looked clean. The interception was happening in the network fabric itself, not on any device a security team would typically monitor.

"Forest Blizzard compromised routers across more than 18,000 networks, intercepting Microsoft 365 session tokens without deploying a single line of malicious code on victim devices."

Why This Campaign Rewrites the Threat Model

The operational elegance of this campaign is what makes it so consequential. Enterprise security investment has flowed heavily toward endpoint protection, email filtering, and MFA enforcement — all of which this attack rendered irrelevant. Forest Blizzard, previously tracked under names including Fancy Bear and APT28 by other intelligence firms, has a documented history of targeting government bodies, defense contractors, energy infrastructure, and media organizations across NATO member states. By operating at the router layer, the group effectively built a passive intelligence collection network inside thousands of homes and offices that persisted undetected for an extended period. The campaign underscores a widening blind spot: the consumer-grade devices that bridge corporate VPN users, remote workers, and cloud services are rarely held to enterprise security standards — yet they now sit in the critical path of sensitive authentication flows.

The Forest Blizzard operation is a structural warning, not just a patching reminder. As hybrid work embeds consumer routers permanently into enterprise access paths, the attack surface for nation-state interception grows faster than most organizations' ability to govern it. Microsoft and CISA are expected to release updated mitigation guidance, likely emphasizing token binding, continuous access evaluation, and router firmware enforcement policies — but for the thousands of organizations already compromised, the session tokens are already gone. The next phase of credential security will have to extend well past the endpoint, all the way down to the forgotten device blinking in the corner of the home office.

Editorial Note

Krebs on Security is a highly reputable cybersecurity news outlet with established credibility for breaking major security incidents. Router exploitation for token harvesting aligns with known Russian state-sponsored APT tactics (Cozy Bear, SVR) documented by CISA and Microsoft. However, the specific claim of '18,000 networks' should be verified against official statements from Microsoft or CISA for exact attribution and scope confirmation.

Claim Tracker

AI-assessed

UnverifiedRussian military intelligence (GRU) linked threat group Forest Blizzard conducted the campaign

Attribution to state actors requires corroborating evidence; attribution is attributed to unnamed 'security experts'

UnverifiedCampaign compromised more than 200 organizations and approximately 5,000 devices

Summary claims 18,000 networks; body states 5,000 devices. Conflicting figures; no source provided

UnverifiedAttackers harvested Microsoft Office authentication tokens without deploying malware or phishing

Technically plausible via router interception, but specific evidence not presented

UnverifiedExploited known vulnerabilities in aging consumer and small-business routers

Claims refer to 'publicly documented vulnerabilities' but specific CVEs not cited

VerifiedStolen tokens bypass both passwords and multi-factor authentication

Technically accurate; compromised session tokens do circumvent MFA

Ask AI about this story

// discussion

sign in to join the discussion