Russia Hacked Routers to Steal Microsoft Office Tokens
Russian military intelligence, operating under the ‘Forest Blizzard’ (APT28/Fancy Bear) moniker, has been conducting a sophisticated cyber espionage campaign targeting over 18,000 routers globally. The attackers exploited vulnerabilities in older, unsupported routers – primarily Mikrotik and TP-Link devices – to steal Microsoft Office authentication tokens, bypassing traditional malware methods. This operation highlights a concerning trend of state-sponsored actors leveraging easily accessible vulnerabilities to gain access to sensitive data, particularly impacting government agencies and organizations reliant on Microsoft Office.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
