Microsoft said the Russian military-linked threat actor Forest Blizzard (APT28/Strontium) has compromised vulnerable home and small-office routers since at least August 2025, changing DNS settings to route traffic through attacker-controlled resolvers. The campaign affected more than 200 organizations and 5,000 consumer devices across government, IT, telecommunications, and energy, turning edge devices into covert infrastructure and giving the actor passive visibility into victims’ DNS traffic.
For selected high-value targets, the operation escalated into adversary-in-the-middle attacks in which spoofed DNS responses redirected users to systems presenting invalid TLS certificates for legitimate services, including Microsoft Outlook on the web and government servers. Microsoft said confirmed AiTM activity included non-Microsoft government targets in at least three African countries, while stressing that no Microsoft-owned assets or services were compromised; the company urged defenders to patch and harden routers, replace default credentials, audit DNS settings, and train users not to bypass certificate warnings.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
Following the disruption of the GRU-linked router botnet, the FBI, NSA, and partners from 15 countries issued a public service announcement urging users to replace unsupported routers, update firmware, verify DNS settings, disable internet-exposed remote management, and change default credentials. The guidance was aimed at reducing continued risk from compromised SOHO routers used in the APT28/Forest Blizzard espionage campaign.
On April 8, 2026, Germany's Federal Office for the Protection of the Constitution, together with BND and the FBI, warned that APT28 had compromised vulnerable TP-Link routers for espionage. The agency said several thousand routers were targeted worldwide, including about 30 vulnerable devices in Germany, and confirmed some compromises that led operators to replace affected routers.
The UK National Cyber Security Centre warned of two Russian-linked APT28/Forest Blizzard campaigns abusing compromised SOHO routers for DNS hijacking and adversary-in-the-middle credential theft. It said one cluster altered DHCP DNS settings while another used compromised MikroTik and TP-Link routers to forward DNS traffic through actor-controlled infrastructure, including activity focused on MikroTik routers in Ukraine.
As part of Operation Masquerade, the FBI carried out a court-authorized technical operation against the U.S. portion of the APT28/Forest Blizzard router network, resetting malicious DNS settings on compromised TP-Link SOHO routers to legitimate ISP resolvers and blocking the attackers’ original access method. The DOJ said affected routers were located in more than 23 U.S. states and that the action was designed not to disrupt normal router functionality or collect users’ content.
A joint operation involving the U.S. Department of Justice, the FBI, and international partners disrupted the malicious infrastructure used in the APT28/Forest Blizzard DNS hijacking campaign. The action targeted infrastructure supporting the compromise of SOHO routers and downstream espionage activity.
On April 7, 2026, Microsoft Threat Intelligence publicly reported the campaign, attributing it to Forest Blizzard, a Russian military-linked threat actor also known as APT28 or Strontium. Microsoft said it was the first observed instance of the group using DNS hijacking at scale to support TLS AiTM operations after edge-device exploitation and noted no Microsoft-owned assets or services were compromised.
In selected cases, the actor escalated from passive DNS collection to adversary-in-the-middle attacks by spoofing DNS responses for Outlook on the web and certain government servers, including activity affecting targets in at least three African nations. Victims were presented invalid TLS certificates, allowing interception of plaintext traffic if certificate warnings were ignored.
Over the course of the campaign, the router compromises led to DNS hijacking impacting more than 200 organizations and 5,000 consumer devices across government, IT, telecommunications, and energy sectors. Microsoft said this represented large-scale abuse of edge devices for downstream victim visibility.
At its peak in December 2025, the APT28-attributed FrostArmada campaign had compromised about 18,000 MikroTik and TP-Link SOHO routers in 120 countries. The operation primarily targeted government agencies, law enforcement organizations, and IT providers by altering DNS settings to enable adversary-in-the-middle credential and token theft.
Since at least August 2025, Microsoft assessed that Forest Blizzard began compromising vulnerable home and small-office routers and changing their DNS settings to actor-controlled resolvers. The activity turned the devices into covert malicious infrastructure for intelligence collection.
The IC3 advisory says Russian GRU actors behind APT28/Forest Blizzard had been exploiting vulnerable SOHO routers worldwide since at least 2024, including TP-Link devices vulnerable to CVE-2023-50224. The compromises enabled changes to DHCP and DNS settings that supported later DNS hijacking and adversary-in-the-middle operations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
27 references tracked. Mallory keeps watching after this page renders.
foxbusiness.com
Open sourcezdnet.fr
Open sourcezdnet.com
Open sourcecyberscoop.com
Open sourcetechcrunch.com
Open sourcego.theregister.com
Open sourcekrebsonsecurity.com
Open sourceic3.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.