Historical intelligence backfill. This assessment covers reporting originally published on 2026-04-07 and was added to the RWP archive on 2026-09-07.
Forest Blizzard did not need malware on the laptop — it needed your home router's DNS
GRU Unit 26165 turned vulnerable SOHO routers into malicious resolvers; Microsoft counted 200+ organizations and 5,000 consumer devices, and DOJ reset US routers the same day.
Bottom line up front
CONFIRMED On 7 April 2026 Microsoft and the US DOJ/FBI published the same campaign from two sides. Forest Blizzard (APT28 / GRU Unit 26165), with Microsoft subgroup Storm-2754, has since at least August 2025 (DOJ: credential theft against TP-Link-class SOHO from at least 2024) changed router DNS to GRU resolvers. Microsoft: 200+ organizations and ~5,000 consumer devices in its telemetry; Microsoft-owned services not compromised. Most victims just leaked DNS. A subset got spoofed answers for Outlook on the web and invalid TLS certs for AiTM. Separate Microsoft-observed AiTM hit non-Microsoft government servers in at least three African countries. DOJ, EDPA, pushed commands to US compromised routers to collect evidence, restore ISP DNS, and close the original hole.
No implant on the PC is required. DHCP hands every laptop the poisoned resolver.
Historical backfill of 7 April 2026 reporting; added 7 September 2026.
What happened
Mass router credential/vuln abuse, DNS hijack, filter for interesting lookups, then targeted spoof. SOCRadar later used an 18,000-router figure; treat that as secondary, not Microsoft's 5,000/200.
Why it mattered
Remote work made the home router part of the Entra perimeter. Certificate warnings on OWA became the only user-visible tell — and users click through those.
OT: UNKNOWN. A plant technician on a hijacked home mesh is an identity path, not a confirmed ICS incident.
Who / what was affected
SOHO/consumer routers; orgs whose staff resolve DNS through those devices; military/government/CI of intelligence interest per DOJ.
Technical context
DoH/DoT on managed endpoints; inspect DNS settings on remote-access users; never click through OWA cert errors; phishing-resistant MFA so a stolen password plus hijacked DNS is still incomplete — tokens are the remaining risk.
Exploitation / threat status at the time
CONFIRMED Microsoft counts, GRU attribution aligned with DOJ, US disruption.
ASSESSED (high): unmanaged consumer routers remain the durable collection layer.
What defenders should have done
- Force secure DNS on corporate laptops regardless of home router.
- Alert on TLS errors to login.microsoftonline / outlook.office.com from remote users.
- Consumer advisory to staff: reboot router, check DNS, change admin password, patch firmware.
RWP assessment
Confidence: High. This is the 2026 version of "the last hop is not yours."
Defensive actions
- DoH enterprise policy.
- Help-desk script for "certificate warning on Outlook."
- Do not treat home-router firmware as out of scope for executives.
Sources
- Microsoft Threat Intelligence — SOHO router compromise leads to DNS hijacking and AiTM
- U.S. Department of Justice — Court-authorized disruption of DNS hijacking network
- TechSpot — Hackers are turning home routers into tools to spy on Microsoft 365 users