Russian hackers APT28 (or Forest Blizzard), have been linked to a new campaign that has compromised MikroTik and TP-Link routers and modified their settings to turn them into malicious infrastructure for further attacks. This is as part of a cyberespionage since May 2025.

The campaign is being tracked as FrostArmada by Lumen's Black Lotus Labs . Microsoft describes it as an attempt to exploit vulnerable home and small office (SOHO) internet devices for the purpose of DNS traffic hijacking and passive network data collection.
“Their technique modified the DNS settings on compromised routers to intercept local network traffic and capture and extract authentication credentials,” Black Lotus Labs said in a report shared with The Hacker News. “When a user searched for a targeted domain, the attacker redirected the traffic to an attacker-in-the-middle (AitM) node, where these credentials were collected and extracted. This approach allowed for a nearly invisible attack that required no interaction from the end user.”
Infrastructure associated with the campaign has been disrupted and disconnected as part of a joint operation in collaboration with the U.S. Department of Justice, the Federal Bureau of Investigation, and other international partners.
See also: North Korean hackers use GitHub as C2 in attacks
The activity is estimated to have begun in May 2025, on a limited scale. This was followed by more extensive router exploitation and DNS redirection in early August. At its peak in December 2025, more than 18,000 unique IP addresses from at least 120 countries were found communicating with APT28 infrastructure.
These efforts focused primarily on government organizations, such as foreign ministries, law enforcement agencies, and third-party email and cloud service providers in countries in North Africa, Central America, Southeast Asia, and Europe.
Microsoft's threat team, in its analysis of the campaign, attributed the activity to APT28 and its subgroup tracked as Storm-2754 . The tech giant said it identified more than 200 organizations and 5,000 consumer devices affected by the attacker's malicious DNS infrastructure
“For state actors like Forest Blizzard, DNS hijacking enables persistent, passive visibility and reconnaissance at scale,” the company said. “By compromising edge devices upstream of larger targets, attackers can exploit less closely monitored or managed assets to penetrate corporate environments.”
DNS hijacking activity has also facilitated AitM attacks that have enabled the theft of passwords, OAuth tokens, and other credentials for web- and email-related services, putting organizations at risk of a broader breach.
See also: Storm-1175: Zero-day exploit for Medusa ransomware deployment

APT28: Targeting routers and new DNS hijacking techniques
The development marks the first time this group has been observed using DNS hijacking at scale to support AitM of Transport Layer Security (TLS) connections after exploiting edge devices.
Typically, the attack chain involves APT28 gaining remote administrative access to SOHO devices and changing the default network settings to use DNS servers under its control. The malicious reconfiguration causes the devices to send their DNS requests to servers controlled by the attacker.
This, in turn, causes DNS lookups for email applications or login pages to be resolved by the malicious DNS server. The attacker then attempts to conduct AitM attacks against these connections to steal user account credentials by tricking victims into connecting to a malicious infrastructure.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Some of these domains are associated with Microsoft Outlook on the web. Microsoft also said it detected AitM activity targeting servers not hosted by Microsoft, at at least three government organizations in Africa.
“DNS hijacking operations are believed to be opportunistic, with the perpetrator gaining visibility into a large pool of potential target users and then filtering users at each stage of the exploitation chain to select victims with potentially valuable information“.
Targeting TP-Link and MikroTik routers
APT28 is said to have exploited TP-Link WR841N routers via CVE-2023-50224 (CVSS score: 6.5), an authentication bypass vulnerability that could be used to extract stored credentials via specially crafted HTTP GET requests.
See also: Iranian password-spraying campaign targets Israeli organizations
According to the Department of Justice, threat actors associated with Military Unit 26165 of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU) have exploited known security vulnerabilities to steal credentials for thousands of TP-Link routers worldwide since at least 2024.

“The attackers then applied an automated filtering process to determine which DNS requests were of interest and warranted interception,” the Justice Department said. “For selected targets, GRU DNS resolvers provided fraudulent DNS records for specific domains that mimicked legitimate services – including Microsoft Outlook Web Access – to facilitate Actor-in-the-Middle attacks against the victims’ encrypted network traffic.”
A second cluster of servers receives DNS requests via compromised routers and then forwards them to remote servers owned by perpetrators. It is estimated that this cluster has also been involved in interactive operations targeting a small number of MikroTik routers located in Ukraine.
Source: thehackernews.com
