ThreatLocker
  • Home
  • News
  • Security
  • Authorities disrupt router DNS hijacks used to steal Microsoft 365 logins

Authorities disrupt router DNS hijacks used to steal Microsoft 365 logins

  • April 7, 2026
  • 11:51 AM
  • 0

Authorities disrupt DNS hijacks used to steal Microsoft 365 logins

An international operation from law enforcement authorities in partnership with private companies has disrupted FrostArmada, an APT28 campaign hijacking local traffic from MikroTik and TP-Link routers to steal Microsoft account credentials.

The Russian threat group APT28, also tracked as Fancy Bear, Sofacy, Forest Blizzard, Strontium, Storm-2754, and Sednit, has been linked to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.

In the FrostArmada attacks, the hackers compromised mainly small office/home office (SOHO) routers and altered the domain name system (DNS) settings to point to virtual private servers (VPS) under their control, which acted as DNS resolvers.

image

This allowed APT28 to intercept authentication traffic to targeted domains and steal Microsoft logins and OAuth tokens.

At its peak in December 2025, FrostArmada infected 18,000 devices across 120 countries, primarily targeting government agencies, law enforcement, IT and hosting providers, and organizations operating their own servers.

Microsoft, whose services were targeted by this campaign, worked together with Black Lotus Labs (BLL), Lumen's threat research and operations division, to map the malicious activity and identify victims.

With support from the FBI, the U.S. Department of Justice, and the Polish government, the offending infrastructure has been taken neutralized. 

FrostArmada activity

The attackers targeted internet-exposed routers, primarily MikroTik and TP-Link, as well as some firewall products from Nethesis and older Fortinet models.

Once compromised, the devices communicated with the attackers’ infrastructure and received DNS configuration changes that redirected traffic to malicious VPS nodes.

The new DNS settings were automatically pushed to internal devices via the Dynamic Host Configuration Protocol (DHCP).

When clients queried authentication-related domains the threat actor targeted, the DNS server returned the attacker’s IP instead of the real one, redirecting victims to an adversary-in-the-middle (AitM) proxy.

DNS request redirection at the router level
DNS request redirection at the router level
Source: Black Lotus Labs

The only visible sign of fraud for the victim would have been a warning for an invalid TLS certificate, which could have easily been dismissed. However, ignoring the alert gave the threat actor access to the victim's unencrypted internet communication.

“The actor essentially ran a proxy service as the AitM that the end user was directed to via DNS,” Lumen's Black Lotus Labs researchers explain.

“The only sign of this attack would be a pop-up warning about connecting to an untrusted source because of the 'break and inspect' configuration.”

“If warnings were present and ignored or clicked through, the actor proxied requests to the legitimate services, collecting the data at the midpoint and collecting data associated with the targeted account by passing the valid OAuth token.”

In some cases, though, the hackers spoofed DNS responses for certain domains, thus forcing affected endpoints to connect to the attack infrastructures, Microsoft says in a report today.

Lumen reports that FrostArmada operated in two distinct clusters, one called the 'Expansion team' dedicated to device compromise and botnet growth, and the second handling the AiTM and credential collection operations.

Overview of the Expansion branch operations
Overview of the Expansion branch operations
Source: Black Lotus Labs

FBI cleaning hacked routers

The U.S. Department of Justice (DoJ) says in a press release today that the FBI carried out "a court-authorized technical operation" to secure compromised routers by removing APT28's resolvers though DNS resets, forcing the devices to connect to legitimate DNS resolvers provided by their internet provider.

The commands delivered to affected routers also allowed the FBI to collect evidence about the threat actor's activity.

To ensure that the commands impact only the hacker's operation and did not affect the router's normal functionality or gather user information, "the government extensively tested the operation on firmware and hardware for affected TP-Link routers."

It is important to note that users can remove any changes made to their devices by resetting them to factory default settings.

The DoJ also provides a set of recommendations for users of SOHO devices to set up defenses:

  1. Replace routers that are no longer receive support
  2. Install the latest firmware version available
  3. Check the DNS resolvers listed in router settings
  4. Review and implement firewall rules to prevent the unwanted exposure of remote management services

According to the DoJ, the state-backed APT28 threat actor has been indiscriminately compromising TP-Link routers since 2024, exploiting known vulnerabilities to steal credentials.

Later, the actor "implemented an automated filtering process to determine which DNS requests were of interest and warranted interception."

Black Lotus Labs researchers report that FrostArmada activity increased sharply following an August 2025 report from the National Cyber Security Centre (NCSC) in the UK describing a Forest Blizzard toolset that targeted Microsoft account credentials and tokens.

Microsoft confirmed that APT28 carried out AitM attacks against domains associated with the Microsoft 365 service, as subdomains for Microsoft Outlook on the web have also been targeted.

Additionally, the company observed this activity on servers belonging to three government organizations in Africa that were not hosted on Microsoft infrastructure. In those attacks, "Forest Blizzard intercepted DNS requests and conducted follow-on collection."

Black Lotus Labs also observed the threat actor targeting entities with on-premise email servers and "a small number of government organizations" in North Africa, Central America, and Southeast Asia.

The researchers note that "there was also a connection to a national identity platform in one European country."

In a report today, the UK agency says that the AitM activity impacted both browser sessions and desktop applications, and the DNS hijacking is believed to have been opportunistic in nature to build a large pool of potential targets and then filtering those of interest.

Black Lotus Labs has published a small set of indicators of compromise for the VPS servers used during the FrostArmada campaign:

IP address First Seen Last Seen
64.120.31[.]96 May 19, 2025 March 31, 2026
79.141.160[.]78 July 19, 2025 March 31, 2026
23.106.120[.]119 July 19, 2025 March 31, 2026
79.141.173[.]211 July 19, 2025 March 31, 2026
185.117.89[.]32 September 9, 2025 September 9, 2025
185.237.166[.]55 December 30, 2025 December 30, 2025

The researchers note that defenders should implement certificate pinning for corporate devices (laptops, mobile phones) controlled via an MDM solution, which would generate an error when the attacker tries to intercept and analyze traffic on their VPS infrastructure.

Another recommendation is to minimize the attack surface through patching, limiting exposure on the public web, and removing all end-of-life equipment.

Microsoft and the NCSC also provide a list of IoCs and protection guidance to help defenders identify and prevent DNS hijacking attacks.

Update [April 7, 18:16 EST]: Article updated with information from the Department of Justice that became available after publishing time.

article image

Test every layer before attackers do

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Related Articles:

TP-Link patches Omada ZTP flaws allowing hackers to breach networks

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

CubePilot drone software dev hit by DNS hijacking to intercept traffic

Hackers abuse ViPNet software to target Russian govt agencies

Russian hackers trojanize WebEx, Zoom apps to push Starland malware

Bill Toulas
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.
Post a Comment Community Rules
You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

Login

Reporter

Help us understand the problem. What is going on with this comment?

Read our posting guidelinese to learn what content is prohibited.

SUBMIT