Russian hackers hijacked thousands of routers in global espionage blitz
A sprawling, state-sponsored cyberattack, orchestrated by Russian intelligence operatives, has compromised over 18,000 routers across more than 120 countries, revealing a sophisticated espionage campaign that authorities are only now fully neutralizing. The operation, dubbed 'Forest Blizzard,' represents a significant escalation in the use of civilian infrastructure for intelligence gathering, impacting everything from government agencies to consumer devices.
Exploiting known vulnerabilities, stealing credentials
The perpetrators, identified as APT28 (also known as Fancy Bear and linked to Russia’s Main Intelligence Directorate, GRU), exploited well-documented vulnerabilities in TP-Link routers, a ubiquitous brand found in homes and businesses worldwide. Rather than developing novel malware, the attackers leveraged existing weaknesses to pilfer credentials, hijack Domain Name System (DNS) settings, and redirect traffic to steal additional tokens—a tactic that highlights the persistent challenge of patching and securing internet-connected devices.
What’s particularly concerning is the scale of the operation. Microsoft Threat Intelligence estimates that over 200 organizations were infiltrated, impacting at least 5,000 individual consumer devices. While Microsoft insists its own corporate assets remained untouched, the ripple effects of the breach are far-reaching, extending to government agencies, IT firms, telecommunications companies, the energy sector, and even national identity platforms in Europe and North Africa.

Fbi operation halts further exploitation
The FBI, in collaboration with federal prosecutors, Lumen’s Black Lotus Labs, and Microsoft Threat Intelligence, launched 'Operation Masquerade'—a court-authorized intervention to reset DNS settings and prevent further exploitation. Brett Leatherman, Assistant Director of the FBI’s Cyber Division, underscored the seriousness of the threat, stating, “Sounding the alarm wasn’t enough. The FBI conducted a court-authorized operation to harden compromised routers across the United States.” The agency also revealed that Russian GRU operatives weaponized routers in over 23 states to steal sensitive government, military, and critical infrastructure data.

Adversary-in-the-middle attacks and targeted domains
Forest Blizzard's tactics weren't limited to router manipulation. Researchers discovered adversary-in-the-middle attacks targeting domains mimicking legitimate services, including Microsoft Outlook Web Access. This deception allowed attackers to intercept usernames, passwords, OAuth tokens, and other sensitive cloud-hosted content—a stark reminder of the human element in cybersecurity and the ease with which attackers can exploit trust.
The operation’s origins can be traced back to August, shortly after the UK’s National Cyber Security Centre published a malware analysis report detailing a tool used to steal Microsoft Office credentials. While the full extent of Forest Blizzard’s data harvesting remains under investigation, Danny Adamitis, a distinguished engineer at Black Lotus Labs, confirmed a crucial development: “The campaign has ceased. We have observed a gradual decline in communications associated with this infrastructure over the past several weeks.”
The lingering question isn’t whether this attack was successful, but how much sensitive information has already been compromised. The incident serves as a chilling demonstration of how easily critical infrastructure can be exploited, and a resounding call for increased vigilance and proactive security measures—not just for governments, but for every individual connected to the internet.
